Teampass
Source repositories
CVEs (50)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-3106 | Med | 0.35 | 5.4 | 0.00 | Mar 31, 2026 | Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or… | ||
| CVE-2023-3095 | Med | 0.35 | 6.5 | 0.00 | Jun 4, 2023 | Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | ||
| CVE-2019-17204 | Med | 0.35 | 5.4 | 0.01 | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item. | ||
| CVE-2019-17203 | Med | 0.35 | 5.4 | 0.01 | Oct 5, 2019 | TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder. | ||
| CVE-2019-16904 | Med | 0.35 | 5.4 | 0.01 | Sep 26, 2019 | TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.) | ||
| CVE-2019-12950 | Med | 0.35 | 5.4 | 0.01 | Aug 6, 2019 | An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload. | ||
| CVE-2024-50703 | Med | 0.28 | 5.4 | 0.00 | Dec 30, 2024 | TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id. | ||
| CVE-2024-50702 | Med | 0.28 | 5.4 | 0.00 | Dec 30, 2024 | TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager. | ||
| CVE-2023-3565 | Med | 0.28 | 5.4 | 0.01 | Jul 10, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | ||
| CVE-2023-3552 | Med | 0.28 | 5.4 | 0.01 | Jul 8, 2023 | Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | ||
| CVE-2023-3531 | Med | 0.28 | 5.4 | 0.01 | Jul 6, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. | ||
| CVE-2023-3191 | Med | 0.28 | 5.4 | 0.01 | Jun 10, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | ||
| CVE-2023-3009 | Med | 0.28 | 5.4 | 0.01 | May 31, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | ||
| CVE-2023-2591 | Med | 0.28 | 5.4 | 0.01 | May 9, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7. | ||
| CVE-2023-2516 | Med | 0.28 | 5.4 | 0.01 | May 5, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7. | ||
| CVE-2023-2021 | Med | 0.28 | 5.4 | 0.00 | Apr 13, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3. | ||
| CVE-2023-1463 | Med | 0.28 | 5.4 | 0.01 | Mar 17, 2023 | Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | ||
| CVE-2017-15051 | Med | 0.28 | 5.4 | 0.01 | Nov 27, 2017 | Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first… | ||
| CVE-2017-15278 | Med | 0.28 | 5.4 | 0.01 | Oct 12, 2017 | Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable… | ||
| CVE-2017-15053 | Med | 0.25 | 4.9 | 0.01 | Nov 27, 2017 | TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated… |
- risk 0.35cvss 5.4epss 0.00
Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or…
- risk 0.35cvss 6.5epss 0.00
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- risk 0.35cvss 5.4epss 0.01
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.
- risk 0.35cvss 5.4epss 0.01
TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.
- risk 0.35cvss 5.4epss 0.01
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)
- risk 0.35cvss 5.4epss 0.01
An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.
- risk 0.28cvss 5.4epss 0.00
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.
- risk 0.28cvss 5.4epss 0.00
TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
- risk 0.28cvss 5.4epss 0.01
Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- risk 0.28cvss 5.4epss 0.01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.
- risk 0.28cvss 5.4epss 0.01
Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
- risk 0.28cvss 5.4epss 0.01
Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first…
- risk 0.28cvss 5.4epss 0.01
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable…
- risk 0.25cvss 4.9epss 0.01
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated…
Page 2 of 3