VendorsPassboltpassbolt_apiall versions
Vulnerabilities

Passbolt API

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-27913
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
Published 2025-03-10 · Analyzed
7.5EPSS 0.002
CVE-2017-1000442
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
Published 2018-01-02 · Modified
5.4EPSS 0.005
CVE-2024-33670
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as JavaScript due to Content Security Policy (CSP) restrictions, it may still impact the appearance and user interaction of the page.
Published 2024-04-26 · Analyzed
4.3EPSS 0.005