Passbolt API
by Passbolt
Source repositories
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27913 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2025 | Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header. | ||
| CVE-2017-1000442 | Med | 0.28 | 5.4 | 0.01 | Jan 2, 2018 | Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace | ||
| CVE-2024-33670 | Med | 0.21 | 4.3 | 0.00 | Apr 26, 2024 | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact… |
- risk 0.49cvss 7.5epss 0.00
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
- risk 0.28cvss 5.4epss 0.01
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
- risk 0.21cvss 4.3epss 0.00
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact…