MyToast
- Known vulnerabilities
- 0
- Still open
- 0
- KEV open
- 0
- Max CVSS (historical)
- —
Cumulative exposure
Low
Aggregates open CVEs (40%) + KEV (30%) + critical shared permissions (15%) + trackers (10%) + OS EOL (5%). Higher score = more exposed.
-
Open CVEs +0/+50
0 open CVEs, max CVSS 0.0, EPSS 0%
-
Active KEVs +0/+35
0 CISA KEVs still open
-
Permissions +0/+10
0 critical shared permission(s)
-
Trackers +0/+8
0 identification/profiling tracker(s)
-
EOL OS +0/+5
Installed OS is end-of-life
Based on permissions only: no CVE data referenced for this app.
Known vulnerabilities (CVE)
No CVE is currently referenced in NVD for this app on its platform.
The absence of CVEs is not a security guarantee — it can also mean nobody has audited or published findings.
Context
Context
Description
The MyToast app allows team members working at Toast restaurants to: • View their past and upcoming shifts along with shift details such as clock-in, clock-out, breaks, and tips. • If team members are paid via Toast Payroll, they can view their earnings by shift and pay period. • Team members with the the My Reports permission can view their stats such as sales, average order, and guests served. • Active team members paid via Toast Payroll can access their Form W-2. • If made available by the employer, team members can order and activate Toast Pay Card. Toast Pay Cards are issued by Sutton Bank, Member FDIC, pursuant to license by Mastercard®. Mastercard and the circles design are registered trademarks of Mastercard International Incorporated. Toast PayOuts are funded by a 0% line of credit issued to employers by Toast, Inc. as set forth in the employer's Credit Agreement. Toast and WebBank each reserve the right to change or discontinue this program at any time. Toast Pay Card and PayOut is not available in all jurisdictions and is available to Toast Payroll customers only.
Data collected and shared
Source: App Store · App Privacy · 4 data item(s) declared
Indicative classification based on data sensitivity. "Shared" = transmitted to third parties (publisher-declared).
FAQ
FAQ: MyToast
Why are no CVEs listed for MyToast?
No CVE is currently referenced in NVD for MyToast (com.toasttab.toastemployee) with a iOS CPE configuration. Either none has been publicly disclosed, or none has been mapped yet. Absence of a CVE is not a security guarantee.
What is the latest known version of MyToast?
The most recent version of MyToast (com.toasttab.toastemployee) tracked by Appaloosa Scout is 1.48.0, published by Toast, Inc..