VendorsXWikicryptpadany version
Vulnerabilities

XWiki CryptPad any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-49591
CryptPad 2FA Bypass Vulnerability
Published 2025-06-18 · Analyzed
9.1EPSS 0.005
CVE-2025-51846
CryptPad unbounded WebSocket frame flood
Published 2026-04-30 · Analyzed
8.7EPSS 0.006
CVE-2019-15302
The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.
Published 2019-09-11 · Modified
6.5EPSS 0.014
CVE-2017-1000051
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content
Published 2017-07-13 · Modified
6.1EPSS 0.012
CVE-2025-49590
CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability
Published 2025-06-18 · Analyzed
6.1EPSS 0.003