VYPR

Bitwarden

by Bitwarden

CVEs (5)

  • CVE-2023-27974HigMar 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Bitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a password stored for an example.com hosting provider when customer-website.example.com is visited. NOTE: the vendor's position is that "Auto-fill on page load" is not enabled by…

  • CVE-2018-25081HigMar 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain configurations (e.g., an apple.com IFRAME element on the icloud.com website) and that "Auto-fill on…

  • CVE-2023-27706HigJun 9, 2023
    risk 0.46cvss 7.1epss 0.01

    Bitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Credential Manager, accessible to other local unprivileged processes.

  • CVE-2025-5138LowMay 25, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component PDF File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2023-38840MedAug 15, 2023
    risk 0.00cvss 5.5epss 0.01

    Bitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive information via the Bitwarden.exe process.