Passbolt Api
Passbolt · 4 CVEs
CVE-2025-27913
LOW
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Healt…
Mar 10, 2025
CVE-2024-33670
MEDIUM
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a…
Apr 26, 2024
CVE-2024-33669
MEDIUM
An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned whi…
Apr 26, 2024
CVE-2017-1000442
MEDIUM
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
Jan 2, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-27913 | Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email message… | LOW | 0.19% | Mar 10, 2025 |
| CVE-2024-33670 | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although th… | MEDIUM | 0.48% | Apr 26, 2024 |
| CVE-2024-33669 | An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which resu… | MEDIUM | 0.64% | Apr 26, 2024 |
| CVE-2017-1000442 | Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace | MEDIUM | 0.52% | Jan 2, 2018 |
Showing 1 to 4 of 4 CVEs