Passbolt

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-27913

    Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.

    Last Modified: Jun 19, 2025
    Published: Mar 10, 2025

    CVE-2024-33669

    An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows an attacker capable of observing Passbolt's HTTPS queries to the Pwned Password API to more easily brute force passwords that are manually typed by the user.

    Last Modified: Jun 18, 2025
    Published: Apr 26, 2024

    CVE-2024-33670

    Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.

    Last Modified: Jun 18, 2025
    Published: Apr 26, 2024

    CVE-2017-1000442

    Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace

    Last Modified: Nov 21, 2024
    Published: Jan 02, 2018
    Items Per Page
    Passbolt Vulnerabilities & Security CVEs | CVE-DB