VYPR
Vendor

Vaultwarden

Products
2
CVEs
6
Across products
8
Status
Private

Products

2

Recent CVEs

6
  • CVE-2024-55225CriJan 9, 2025
    risk 0.57cvss 9.8epss 0.01

    An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.

  • CVE-2024-55224CriJan 9, 2025
    risk 0.55cvss 9.6epss 0.01

    An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.

  • CVE-2024-39924HigSep 13, 2024
    risk 0.51cvss 8.8epss 0.13

    An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an attacker with granted emergency…

  • CVE-2024-39925MedSep 13, 2024
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. It lacks an offboarding process for members who leave an organization. As a result, the shared organization key is not rotated when a member departs. Consequently, the departing member, whose access should be…

  • CVE-2024-55226MedJan 9, 2025
    risk 0.28cvss 5.4epss 0.00

    Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.

  • CVE-2024-39926MedSep 13, 2024
    risk 0.28cvss 5.4epss 0.00

    An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious…