KeePassXC records
4 published records for vendor keepassxc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-316 Cleartext Storage of Sensitive Information in Memory2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
28Monitor | CVE-2025-65203No exploit | KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directivkeepassxc · keepassxc-browser · CWE-352 | High7.1 | — | 0.1% | Dec 17, 2025 |
26Monitor | CVE-2024-33901Proof of concept | Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database vikeepassxc · keepassxc · CWE-316 | Medium6.5 | — | 0.7% | May 20, 2024 |
26Monitor | CVE-2024-33900No exploit | KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump.keepassxc · keepassxc · CWE-316 | Medium6.5 | — | 0.3% | May 20, 2024 |
22Monitor | CVE-2023-35866No exploit | In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factorkeepassxc · keepassxc · CWE-863 | Medium5.5 | — | 0.2% | Jun 19, 2023 |
- CVE-2025-6520328Monitor
KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directiv
HighCVSS 7.1No exploitEPSS 0%keepassxc · keepassxc-browserDec 17, 2025
- CVE-2024-3390126Monitor
Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database vi
MediumCVSS 6.5Proof of conceptEPSS 1%keepassxc · keepassxcMay 20, 2024
- CVE-2024-3390026Monitor
KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump.
MediumCVSS 6.5No exploitEPSS 0%keepassxc · keepassxcMay 20, 2024
- CVE-2023-3586622Monitor
In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor
MediumCVSS 5.5No exploitEPSS 0%keepassxc · keepassxcJun 19, 2023