TeamPasswordManager
Products
1- 5 CVEs
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-84699 | Cri | 0.59 | 9.1 | 0.00 | Sep 2, 2026 | Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access. | ||
| CVE-2021-44036 | Hig | 0.57 | 8.8 | 0.00 | Nov 19, 2021 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import. | ||
| CVE-2021-44037 | Hig | 0.49 | 7.5 | 0.01 | Nov 19, 2021 | Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning. | ||
| CVE-2019-19461 | Med | 0.35 | 5.4 | 0.01 | Mar 16, 2020 | Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title. | ||
| CVE-2025-26091 | Med | 0.30 | 4.6 | 0.00 | Mar 4, 2025 | A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new… |
- risk 0.59cvss 9.1epss 0.00
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
- risk 0.57cvss 8.8epss 0.00
Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.
- risk 0.49cvss 7.5epss 0.01
Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
- risk 0.35cvss 5.4epss 0.01
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.
- risk 0.30cvss 4.6epss 0.00
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new…