Clickstudios develops Passwordstate, a widely deployed privileged-access management and password-vault solution that sits in the authentication and authorization path for many organizations. Its vulnerability profile concentrates on web-application and access-control weaknesses—cross-site scripting, privilege and authorization bypasses, and CSRF flaws—that are characteristic of complex credential-management platforms handling sensitive authentication state. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clickstudios over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-3875HIGH A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component | Dec 19, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-26061HIGH ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the | Oct 5, 2020 | 7.5 | 25 | NO | NO |
CVE-2022-4613MEDIUM A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as critical. This issue affects some unknown processing of the co | Dec 19, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-4612MEDIUM A vulnerability has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome and classified as problematic. This vulnerability affects unknown code. The | Dec 19, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-25570MEDIUM In Click Studios (SA) Pty Ltd Passwordstate 9435, users with access to a passwordlist can gain access to additional password lists without permissions. Specifically, an authenticat | Mar 21, 2022 | 6.5 | 22 | NO | NO |
CVE-2020-27747MEDIUM An issue was discovered in Click Studios Passwordstate 8.9 (Build 8973).If the user of the system has assigned himself a PIN code for entering from a mobile device using the built- | Oct 29, 2020 | 6.8 | 22 | NO | NO |
CVE-2022-4611MEDIUM A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This affects an unknown part. The manipul | Dec 19, 2022 | 5.3 | 21 | NO | NO |
CVE-2022-4610MEDIUM A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unkno | Dec 19, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-3877MEDIUM A vulnerability, which was classified as problematic, was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected is an unknown function of the co | Dec 19, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-3876MEDIUM A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This issue affects some unknown proc | Dec 19, 2022 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clickstudios.
Media articles that mention a CVE ID that affects a product developed by Clickstudios — matched by CVE ID, not by vendor name.