Vulnerability index

Browse CVEs

44 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Teampass MEDIUM 5.4
CVE-2026-3106

Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' paramet…

Fix: 3.1.5.24+
Fix from $1,600 2026-03-31
Teampass MEDIUM 5.4
CVE-2026-3107

Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpo…

Fix: 3.1.5.24+
Fix from $1,600 2026-03-31
Teampass HIGH 8.1
CVE-2024-50703

TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.

Fix: 3.1.3.1+
Fix from $1,950 2024-12-30
Teampass MEDIUM 5.3
CVE-2024-50702

TeamPass before 3.1.3.1 does not properly check whether a mail_me (aka action_mail) operation is on behalf of an administrator or manager.

Fix: 3.1.3.1+
Fix from $1,600 2024-12-30
Teampass MEDIUM 5.4
CVE-2023-3565

Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Fix: 3.0.10+
Fix from $1,600 2023-07-10
Teampass HIGH 7.5
CVE-2023-3553

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Fix: 3.0.10+
Fix from $1,950 2023-07-08
Teampass MEDIUM 5.4
CVE-2023-3552

Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Fix: 3.0.10+
Fix from $1,600 2023-07-08
Teampass HIGH 7.2
CVE-2023-3551

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Fix: 3.0.10+
Fix from $1,950 2023-07-08
Teampass MEDIUM 5.4
CVE-2023-3531

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Fix: 3.0.10+
Fix from $1,600 2023-07-06
Teampass MEDIUM 5.4
CVE-2023-3191

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $1,600 2023-06-10
Teampass MEDIUM 6.5
CVE-2023-3095

Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $1,600 2023-06-04
Teampass CRITICAL 9.0
CVE-2023-3086

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $2,300 2023-06-03
Teampass HIGH 8.1
CVE-2023-3084

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $1,950 2023-06-03
Teampass HIGH 8.7
CVE-2023-3083

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $1,950 2023-06-03
Teampass MEDIUM 5.4
CVE-2023-3009

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $1,600 2023-05-31
Teampass HIGH 8.8
CVE-2023-2859

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Fix: 3.0.9+
Fix from $1,950 2023-05-24
Teampass MEDIUM 5.4
CVE-2023-2591

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

Fix: 3.0.7+
Fix from $1,600 2023-05-09
Teampass MEDIUM 5.4
CVE-2023-2516

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

Fix: 3.0.7+
Fix from $1,600 2023-05-05
Teampass MEDIUM 5.4
CVE-2023-2021

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.

Fix: 3.0.3+
Fix from $1,600 2023-04-13
Teampass HIGH 7.5
CVE-2023-1545EPSS 8%

SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

Fix: 3.0.0.23+
Fix from $1,950 2023-03-21
Teampass MEDIUM 5.4
CVE-2023-1463

Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

Fix: 3.0.0.23+
Fix from $1,600 2023-03-17
Teampass HIGH 7.1
CVE-2023-1070

External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

Fix: 3.0.0.22+
Fix from $1,950 2023-02-27
Teampass MEDIUM 6.1
CVE-2022-26980

Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.

Patch available
Fix from $1,600 2022-03-28
Teampass HIGH 8.1
CVE-2020-11671

Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPa…

Fix: after 2.1.27.36
Fix from $1,950 2020-05-04
Teampass HIGH 8.8
CVE-2020-12479

TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.q…

No fix yet
Fix from $1,950 2020-04-29
Teampass HIGH 7.5
CVE-2020-12477

The REST API functions in TeamPass 2.1.27.36 allow any user with a valid API token to bypass IP address whitelist restrictions via an X-Forwarded-For…

No fix yet
Fix from $1,950 2020-04-29
Teampass HIGH 7.5
CVE-2020-12478EPSS 8%

TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.

No fix yet
Fix from $1,950 2020-04-29
Teampass MEDIUM 6.1
CVE-2019-17205

TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of fai…

No fix yet
Fix from $1,600 2019-10-05
Teampass MEDIUM 5.4
CVE-2019-17204

TeamPass 2.1.27.36 allows Stored XSS by setting a crafted Knowledge Base label and adding any available item.

No fix yet
Fix from $1,600 2019-10-05
Teampass MEDIUM 5.4
CVE-2019-17203

TeamPass 2.1.27.36 allows Stored XSS at the Search page by setting a crafted password for an item in any folder.

No fix yet
Fix from $1,600 2019-10-05