VYPR
Vendor

Password Pusher

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2024-51989HigNov 7, 2024
    risk 0.46cvss 7.1epss 0.00

    Password Pusher is an open source application to communicate sensitive information over the web. A cross-site scripting (XSS) vulnerability was identified in the PasswordPusher application, affecting versions `v1.41.1` through and including `v.1.48.0`. The issue arises from an…

  • CVE-2026-62382MedAug 22, 2026
    risk 0.38cvss epss 0.00

    PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true,…

  • CVE-2026-41308MedMay 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated creation of file-type pushes through a generic JSON API create path under certain…

  • CVE-2026-61458HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.00

    PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and per-push lockout mechanisms. Attackers who know a push token can systematically guess passphrases at 120 attempts per minute without…