Known Vulnerabilities for products from Teampass

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Teampass".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-3107 json Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import fu... Not Provided 2026-03-31 2026-04-07
CVE-2026-3106 json Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in ... Not Provided 2026-03-31 2026-04-07
CVE-2023-3565 json Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10. 5.4 - MEDIUM 2023-07-10 2023-07-19
CVE-2023-3553 json Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10. 7.5 - HIGH 2023-07-08 2023-07-14
CVE-2023-3552 json Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.10. 5.4 - MEDIUM 2023-07-08 2023-07-14
CVE-2023-3551 json Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10. 7.2 - HIGH 2023-07-08 2023-07-14
CVE-2023-3531 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10. 5.4 - MEDIUM 2023-07-06 2023-07-11
CVE-2023-3191 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 5.4 - MEDIUM 2023-06-10 2023-06-15
CVE-2023-3190 json Improper Encoding or Escaping of Output in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 4.6 - MEDIUM 2023-06-10 2023-06-15
CVE-2023-3095 json Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 6.5 - MEDIUM 2023-06-04 2023-06-09
CVE-2023-3086 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 9 - CRITICAL 2023-06-03 2023-06-09
CVE-2023-3084 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 8.1 - HIGH 2023-06-03 2023-06-09
CVE-2023-3083 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 8.7 - HIGH 2023-06-03 2023-06-09
CVE-2023-3009 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 5.4 - MEDIUM 2023-05-31 2023-06-06
CVE-2023-2859 json Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. 8.8 - HIGH 2023-05-24 2023-05-30
CVE-2023-2591 json Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/tea... 5.4 - MEDIUM 2023-05-09 2023-05-15
CVE-2023-2516 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7. 5.4 - MEDIUM 2023-05-05 2023-05-10
CVE-2023-2021 json Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3. 5.4 - MEDIUM 2023-04-13 2023-04-21
CVE-2023-1545 json SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. 7.5 - HIGH 2023-03-21 2023-03-24
CVE-2023-1463 json Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. 5.4 - MEDIUM 2023-03-17 2023-04-26

Known software with vulnerabilities from Teampass

Type Vendor Product Version
ApplicationTeampassTeampass2.1