VYPR
High severity7.5NVD Advisory· Published Mar 9, 2023· Updated Jun 17, 2026

CVE-2018-25081

CVE-2018-25081

Description

Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME element on the icloud.com website) and that "Auto-fill on page load" is not enabled by default.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:bitwarden:bitwarden:*:*:*:*:browser:*:*:*+ 2 more
    • cpe:2.3:a:bitwarden:bitwarden:*:*:*:*:browser:*:*:*range: <=2023.2.1
    • (no CPE)
    • (no CPE)range: <=2023.2.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.