Записи Passbolt
4 опубликованных записей вендора passbolt.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 75 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-348 Use of Less Trusted Source1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
4 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
27Наблюдать | CVE-2024-33669Эксплойта нет | An issue was discovered in Passbolt Browser Extension before 4.6.2.passbolt · passbolt browser extension · CWE-200 | Средняя6,8 | — | 0,6 % | 25 апр. 2024 г. |
21Наблюдать | CVE-2017-1000442Эксплойта нет | Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspacepassbolt · passbolt api · CWE-79 | Средняя5,4 | — | 0,5 % | 2 янв. 2018 г. |
17Наблюдать | CVE-2024-33670Эксплойта нет | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the craftpassbolt · passbolt api · CWE-79 | Средняя4,3 | — | 0,5 % | 25 апр. 2024 г. |
8Наблюдать | CVE-2025-27913Эксплойта нет | Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), canpassbolt · passbolt api · CWE-348 | Низкая2,1 | — | 0,2 % | 10 мар. 2025 г. |
- CVE-2024-3366927Наблюдать
An issue was discovered in Passbolt Browser Extension before 4.6.2.
СредняяCVSS 6,8Эксплойта нетEPSS 1 %passbolt · passbolt browser extension25 апр. 2024 г.
- CVE-2017-100044221Наблюдать
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
СредняяCVSS 5,4Эксплойта нетEPSS 1 %passbolt · passbolt api2 янв. 2018 г.
- CVE-2024-3367017Наблюдать
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the craft
СредняяCVSS 4,3Эксплойта нетEPSS 0 %passbolt · passbolt api25 апр. 2024 г.
- CVE-2025-279138Наблюдать
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can
НизкаяCVSS 2,1Эксплойта нетEPSS 0 %passbolt · passbolt api10 мар. 2025 г.