Passbolt
Products
3- 3 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27913 | Hig | 0.49 | 7.5 | 0.00 | Mar 10, 2025 | Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header. | ||
| CVE-2024-33669 | Med | 0.40 | 6.1 | 0.01 | Apr 26, 2024 | An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password… | ||
| CVE-2017-1000442 | Med | 0.28 | 5.4 | 0.01 | Jan 2, 2018 | Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace | ||
| CVE-2024-33670 | Med | 0.21 | 4.3 | 0.00 | Apr 26, 2024 | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact… |
- risk 0.49cvss 7.5epss 0.00
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password…
- risk 0.28cvss 5.4epss 0.01
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
- risk 0.21cvss 4.3epss 0.00
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact…