Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bitwarden

First CVE: Dec 12, 2019Active for: 7 yearsTotal CVEs: 14
36.0
VTI Score
Medium

Bitwarden is a password-management and vault platform whose focused vulnerability footprint centers on authentication, authorization, and sensitive-data handling in its server and core application products. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and cluster around access-control weaknesses, cleartext storage of credentials and secrets, and code-injection vectors that reflect the high-value nature of a centralized credential store. Defenders should monitor this vendor's releases closely given the sensitive data at stake; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bitwarden over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2019
6 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-60104HIGH
Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to the authenticated caller, allowing a low-privileged organizat
Jul 8, 20268.739NONO
CVE-2026-43639CRITICAL
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST
May 11, 20269.137NONO
CVE-2026-42994CRITICAL
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
May 1, 20269.837NONO
CVE-2026-43640HIGH
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user wi
May 11, 20268.135NONO
CVE-2026-57520HIGH
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an o
Jun 25, 20267.129NONO
CVE-2020-15879HIGH
Bitwarden Server 1.35.1 allows SSRF because it does not consider certain IPv6 addresses (ones beginning with fc, fd, fe, or ff, and the :: address) and certain IPv4 addresses (0.0.
Jul 21, 20207.526NONO
CVE-2026-43638MEDIUM
Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /cip
May 11, 20265.425NONO
CVE-2026-57522MEDIUM
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integr
Jun 25, 20265.024NONO
CVE-2018-25081HIGH
Bitwarden through 2023.2.1 offers password auto-fill within a cross-domain IFRAME element. NOTE: the vendor's position is that there have been important legitimate cross-domain con
Mar 9, 20237.524NONO
CVE-2019-19766HIGH
The Bitwarden server through 1.32.0 has a potentially unwanted KDF.
Dec 12, 20197.524NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
29%
57%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (14.3%)
Network12 (85.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (92.9%)
Unknown0 (0.0%)
Required1 (7.1%)
Privileges Required
Low8 (57.1%)
High1 (7.1%)
None5 (35.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bitwarden.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bitwarden — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bitwarden's Products

View all 2 CNAs →

Top CWEs