VYPR

Teampass

by Nilsteampassnet

Source repositories

CVEs (50)

  • CVE-2026-3106MedMar 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or…

  • CVE-2023-3095MedJun 4, 2023
    risk 0.35cvss 6.5epss 0.00

    Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2019-17204MedOct 5, 2019
    risk 0.35cvss 5.4epss 0.01

    TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.

  • CVE-2019-17203MedOct 5, 2019
    risk 0.35cvss 5.4epss 0.01

    TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.

  • CVE-2019-16904MedSep 26, 2019
    risk 0.35cvss 5.4epss 0.01

    TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)

  • CVE-2019-12950MedAug 6, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.

  • CVE-2024-50703MedDec 30, 2024
    risk 0.28cvss 5.4epss 0.00

    TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.

  • CVE-2024-50702MedDec 30, 2024
    risk 0.28cvss 5.4epss 0.00

    TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.

  • CVE-2023-3565MedJul 10, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2023-3552MedJul 8, 2023
    risk 0.28cvss 5.4epss 0.01

    Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2023-3531MedJul 6, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2023-3191MedJun 10, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-3009MedMay 31, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-2591MedMay 9, 2023
    risk 0.28cvss 5.4epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

  • CVE-2023-2516MedMay 5, 2023
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

  • CVE-2023-2021MedApr 13, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.

  • CVE-2023-1463MedMar 17, 2023
    risk 0.28cvss 5.4epss 0.01

    Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

  • CVE-2017-15051MedNov 27, 2017
    risk 0.28cvss 5.4epss 0.01

    Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or (2) user log history. To exploit the vulnerability, the attacker must be first…

  • CVE-2017-15278MedOct 12, 2017
    risk 0.28cvss 5.4epss 0.01

    Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable…

  • CVE-2017-15053MedNov 27, 2017
    risk 0.25cvss 4.9epss 0.01

    TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the application, or delete any arbitrary role. To exploit the vulnerability, an authenticated…