ZeroHour

Vulnerabilities

46 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-3106
+1 in the same advisory: …3107
Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the l

Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in the username field. As a result, arbitrary JavaScript code is automatically executed in the administrator's browser when viewing failed login entries, resulting in a blind XSS condition.

NVD description · AI analysis pending
9.3<1%
  • teampass teampass
CVE-2025-26091
A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScri

A Cross Site Scripting (XSS) vulnerability exists in TeamPasswordManager v12.162.284 and before that could allow a remote attacker to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'name' parameter when creating a new password in the "My Passwords" page.

NVD description · AI analysis pending
4.6<1% PoC
  • teampasswordmanager team password manager
CVE-2024-50703
+2 in the same advisory: …50702 …50701
TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.

TeamPass before 3.1.3.1 does not properly prevent a user from acting with the privileges of a different user_id.

NVD description · AI analysis pending
8.1
group max
<1%
  • teampass teampass
CVE-2023-3565
Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Cross-site Scripting (XSS) - Generic in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2023-3553
+2 in the same advisory: …3551 …3552
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • teampass teampass
CVE-2023-3531
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.10.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2023-3191
+1 in the same advisory: …3190
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • teampass teampass
CVE-2023-3095
Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Improper Access Control in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

NVD description · AI analysis pending
6.5<1% PoC
  • teampass teampass
CVE-2023-3086
+2 in the same advisory: …3083 …3084
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

NVD description · AI analysis pending
9.0
group max
<1% PoC
  • teampass teampass
CVE-2023-3009
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2023-2859
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.

NVD description · AI analysis pending
8.82% PoC
  • teampass teampass
CVE-2023-2591
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2023-2516
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.7.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2023-2021
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.

Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.3.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2023-1545
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

NVD description · AI analysis pending
7.58% PoC
  • teampass teampass
CVE-2023-1463
Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

Authorization Bypass Through User-Controlled Key in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2023-1070
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.

NVD description · AI analysis pending
7.1<1% PoC
  • teampass teampass
CVE-2022-26980
Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.

Teampass 2.1.26 allows reflected XSS via the index.php PATH_INFO.

NVD description · AI analysis pending
6.11% PoC
  • teampass teampass
CVE-2021-44036
+1 in the same advisory: …44037
Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.

Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.

NVD description · AI analysis pending
8.8
group max
<1%
  • teampasswordmanager team password manager
CVE-2020-11671
Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administ

Lack of authorization controls in REST API functions in TeamPass through 2.1.27.36 allows any TeamPass user with a valid API token to become a TeamPass administrator and read/modify all passwords via authenticated api/index.php REST API calls. NOTE: the API is not available by default.

NVD description · AI analysis pending
8.11% PoC
  • teampass teampass
CVE-2020-12479
+2 in the same advisory: …12478 …12477
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php

TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory traversal.

NVD description · AI analysis pending
8.8
group max
3% PoC
  • teampass teampass
CVE-2019-19461
Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with H

Post-authentication Stored XSS in Team Password Manager through 7.93.204 allows attackers to steal other users' credentials by creating a shared password with HTML code as the title.

NVD description · AI analysis pending
5.4<1%
  • teampasswordmanager team password manager
CVE-2019-17205
+2 in the same advisory: …17204 …17203
TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt.

TeamPass 2.1.27.36 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the XSS payload will be executed.

NVD description · AI analysis pending
6.1
group max
1% PoC
  • teampass teampass
CVE-2019-16904
TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin.

TeamPass 2.1.27.36 allows Stored XSS by setting a crafted password for an item in a common available folder or sharing the item with an admin. (The crafted password is exploitable when viewing the change history of the item or tapping on the item.)

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2019-12950
An issue was discovered in TeamPass 2.1.27.35.

An issue was discovered in TeamPass 2.1.27.35. From the sources/items.queries.php "Import items" feature, it is possible to load a crafted CSV file with an XSS payload.

NVD description · AI analysis pending
5.4<1% PoC
  • teampass teampass
CVE-2019-1000001
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared p

TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recoverable server side. This attack appears to be exploitable via any vulnerability that can bypass authentication or role assignment and can lead to shared password leakage.

NVD description · AI analysis pending
9.82%
  • teampass teampass
CVE-2017-15055
+4 in the same advisory: …15054 …15051 …15053 …15052
TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php.

TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, edit any item within a read-only directory, delete an arbitrary item, delete the file attachments of an arbitrary item, copy the password of an arbitrary item to the copy/paste buffer, access the history of an arbitrary item, and edit attributes of an arbitrary directory. To exploit the vulnerability, an authenticated attacker must tamper with the requests sent directly, for example by changing the "item_id" parameter when invoking "copy_item" on items.queries.php.

NVD description · AI analysis pending
8.1
group max
1% PoC
  • teampass teampass
CVE-2017-15278
Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9.

Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

NVD description · AI analysis pending
5.4<1%
  • teampass teampass
CVE-2017-9436
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.

TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.

NVD description · AI analysis pending
9.81%
  • teampass teampass