VYPR

Server

by Bitwarden

Source repositories

CVEs (11)

  • CVE-2019-19766HigDec 12, 2019
    risk 0.49cvss 7.5epss 0.01

    The Bitwarden server through 1.32.0 has a potentially unwanted KDF.

  • CVE-2026-43640HigMay 11, 2026
    risk 0.46cvss 8.1epss 0.01

    Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management privileges to obtain the key using only a valid session.

  • CVE-2026-43639HigMay 11, 2026
    risk 0.45cvss 8.0epss 0.01

    Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{providerId}/clients/existing`, resulting in takeover of the target organization;…

  • CVE-2026-71959MedAug 10, 2026
    risk 0.31cvss 5.8epss 0.00

    Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing any authenticated user to write forged, arbitrarily backdated entries into any organization's audit log.

  • CVE-2026-43638MedMay 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organization` by submitting an empty `collections` array, which causes the server-side…

  • CVE-2025-5138LowMay 25, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component PDF File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2026-60104HigJul 8, 2026
    risk 0.00cvss 8.7epss 0.00

    Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organization member to obtain another user's vault key and a victim-scoped access token by creating a…

  • CVE-2026-57522LowJun 25, 2026
    risk 0.00cvss 3.5epss 0.00

    Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates without JSON encoding. When an organization has configured an event integration…

  • CVE-2026-57521MedJun 25, 2026
    risk 0.00cvss 4.3epss 0.00

    Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organizationId to the PreviewInvoiceController endpoints without membership or authorization…

  • CVE-2026-57520HigJun 25, 2026
    risk 0.00cvss 7.1epss 0.00

    Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by exploiting a missing role hierarchy check in the bulk user-remove endpoint.…

  • CVE-2020-15879HigJul 21, 2020
    risk 0.00cvss 7.5epss 0.03

    Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.0.0/8, 127.0.0.0/8, and 169.254.0.0/16).