VYPR
Vendor

Nilsteampassnet

Products
2
CVEs
50
Across products
69
Status
Private

Products

2

Recent CVEs

50
View all 50 CVEs →
  • CVE-2019-1000001CriFeb 4, 2019
    risk 0.64cvss 9.8epss 0.02

    TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass…

  • CVE-2017-9436CriJun 5, 2017
    risk 0.64cvss 9.8epss 0.01

    TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.

  • CVE-2015-7564CriApr 12, 2017
    risk 0.60cvss 9.8epss 0.03

    Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b)…

  • CVE-2020-11671HigMay 4, 2020
    risk 0.53cvss 8.1epss 0.01

    Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by…

  • CVE-2015-7563HigApr 12, 2017
    risk 0.53cvss 8.8epss 0.03

    Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.

  • CVE-2023-3086CriJun 3, 2023
    risk 0.52cvss 9.0epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-3083HigJun 3, 2023
    risk 0.50cvss 8.7epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2023-2859HigMay 24, 2023
    risk 0.50cvss 8.8epss 0.02

    Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2020-12478HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.08

    TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

  • CVE-2020-12477HigApr 29, 2020
    risk 0.49cvss 7.5epss 0.02

    The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For client HTTP header to the getIp function.

  • CVE-2023-3084HigJun 3, 2023
    risk 0.46cvss 8.1epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

  • CVE-2017-15055HigNov 27, 2017
    risk 0.46cvss 8.1epss 0.01

    TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the…

  • CVE-2023-1545HigMar 21, 2023
    risk 0.45cvss 7.5epss 0.08

    SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

  • CVE-2023-3553HigJul 8, 2023
    risk 0.42cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2017-15054HigNov 27, 2017
    risk 0.42cvss 7.5epss 0.04

    An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerability, an authenticated attacker has to tamper with parameters of a request to…

  • CVE-2023-3551HigJul 8, 2023
    risk 0.40cvss 7.2epss 0.01

    Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

  • CVE-2022-26980MedMar 28, 2022
    risk 0.40cvss 6.1epss 0.01

    Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.

  • CVE-2023-1070HigFeb 27, 2023
    risk 0.39cvss 7.1epss 0.01

    External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

  • CVE-2015-7562MedApr 12, 2017
    risk 0.36cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role.

  • CVE-2026-3107MedMar 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import…