← Vulnerability feed

Vulnerability record · CVE-2020-35774 · published 29 December 2020

CVE-2020-35774: TwitterServer /histograms endpoint cross-site scripting

Twitter · Twitter Server

TwitterServer before 20.12.0 contains a reflected cross-site scripting flaw in server/handler/HistogramQueryHandler.scala that affects the /histograms endpoint in some configurations. An attacker who can get a victim to load a crafted URL can execute script in the victim's browser within the context of the affected service.

5.4 CVSS 3.1 Medium EPSS 86% · top 0.3% CWE-79 · Cross-site scripting
5.4CVSS 3.1 base score, v2 3.5
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityCVSS rates it medium (5.4) and it requires low privileges plus user interaction, but the very high EPSS score and scope change warrant prompt patching.

What it is

TwitterServer before 20.12.0 contains a reflected cross-site scripting flaw in server/handler/HistogramQueryHandler.scala that affects the /histograms endpoint in some configurations. An attacker who can get a victim to load a crafted URL can execute script in the victim's browser within the context of the affected service.

Impact

An attacker can run arbitrary script in a victim's browser session against the TwitterServer admin interface, potentially reading data or performing actions as that user. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.

Attack surface

Reached over the network via the /histograms HTTP endpoint. The CVSS vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs some authenticated access plus a victim who follows a crafted link.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is very high (0.85649, 99.7th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade twitter-server to 20.12.0 or later, which contains the patch commit e0aeb87e89a6e6c711214ee2de0dd9f6e5f9cb6c.
  • If upgrade is not immediate, restrict network access to the /histograms endpoint and the admin interface to trusted networks only.
  • Disable or remove the histograms handler in configurations where it is not required.
  • Apply output encoding or a Content-Security-Policy to admin endpoints to reduce script execution risk.
  • Audit who has access to the admin interface and reduce privileges where possible.

Detection

  • Monitor web logs for requests to /histograms containing script-like or encoded payloads in query parameters.
  • Alert on unexpected script content or reflected input in responses from the /histograms endpoint.
  • Review access logs for the admin interface from unusual source addresses or sessions.
  • Track twitter-server versions in inventory to identify hosts still below 20.12.0.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-35774 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed6.1CVE-2025-66376Zimbra Collaboration Classic UI stored XSS via CSS @import in emailZimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directi…KEVEPSS 20%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed5.4CVE-2021-26829OpenPLC ScadaBR stored XSS via system_settings.shtmOpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored cross-site scripting through system_settings.shtm. Because the inj…KEVEPSS 48%analysed5.4CVE-2025-27915Zimbra Classic Web Client stored XSS via ICS file HTMLZimbra Collaboration Suite 9.0, 10.0 and 10.1 fail to sanitize HTML content in ICS files in the Classic Web Client. A malicious ICS entry embedded in…KEVEPSS 4.0%analysed

Source: NIST National Vulnerability Database (record CVE-2020-35774), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.