syspass records
7 published records for vendor syspass.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-326 Inadequate Encryption Strength1
- CWE-73 External Control of File Name or Path1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2025-25477No exploit | A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be syspass · syspass · CWE-74 | High8.1 | — | 0.4% | Feb 27, 2025 |
30Monitor | CVE-2017-5999No exploit | An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers.syspass · syspass · CWE-326 | High7.5 | — | 1.1% | Mar 6, 2017 |
26Monitor | CVE-2025-25478No exploit | The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames.syspass · syspass · CWE-73 | Medium6.5 | — | 0.4% | Feb 28, 2025 |
24Monitor | CVE-2017-9306No exploit | inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" susyspass · syspass · CWE-79 | Medium6.1 | — | 0.9% | May 31, 2017 |
24Monitor | CVE-2024-42904No exploit | A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a craftesyspass · syspass · CWE-79 | Medium6.1 | — | 0.3% | Sep 3, 2024 |
21Monitor | CVE-2022-4930No exploit | nuxsmin sysPass URL cross site scriptingsyspass · syspass · CWE-79 | Medium5.4 | — | 0.5% | Mar 6, 2023 |
21Monitor | CVE-2025-25476No exploit | A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javsyspass · syspass · CWE-79 | Medium5.4 | — | 0.3% | Feb 28, 2025 |
- CVE-2025-2547732Monitor
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be
HighCVSS 8.1No exploitEPSS 0%syspass · syspassFeb 27, 2025
- CVE-2017-599930Monitor
An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers.
HighCVSS 7.5No exploitEPSS 1%syspass · syspassMar 6, 2017
- CVE-2025-2547826Monitor
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames.
MediumCVSS 6.5No exploitEPSS 0%syspass · syspassFeb 28, 2025
- CVE-2017-930624Monitor
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" su
MediumCVSS 6.1No exploitEPSS 1%syspass · syspassMay 31, 2017
- CVE-2024-4290424Monitor
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafte
MediumCVSS 6.1No exploitEPSS 0%syspass · syspassSep 3, 2024
- CVE-2022-493021Monitor
nuxsmin sysPass URL cross site scripting
MediumCVSS 5.4No exploitEPSS 1%syspass · syspassMar 6, 2023
- CVE-2025-2547621Monitor
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Jav
MediumCVSS 5.4No exploitEPSS 0%syspass · syspassFeb 28, 2025