Xwiki / Cryptpad
5 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-51846 | CryptPad unbounded WebSocket frame flood | HIGH | 8.7 | Apr 30, 2026 |
| CVE-2025-49591 | CryptPad 2FA Bypass Vulnerability | HIGH | 7.4 | Jun 18, 2025 |
| CVE-2025-49590 | CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability | LOW | 2.9 | Jun 18, 2025 |
| CVE-2019-15302 | The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to co… | MEDIUM | 6.5 | Sep 11, 2019 |
| CVE-2017-1000051 | Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via t… | MEDIUM | 6.1 | Jul 13, 2017 |
Showing 1 to 5 of 5 CVEs