Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cryptomator

First CVE: Feb 19, 2022Active for: 4 yearsTotal CVEs: 10
24.4
VTI Score
Low

Cryptomator is a focused file-encryption utility designed to protect data at rest in cloud storage, where its vulnerability profile centers on a single product but carries significance due to the sensitivity of the cryptographic and storage-integrity functions it provides. The recurring weaknesses—including improper restriction of communication channels, integrity-check validation issues, origin validation errors, UI misrepresentation of security-critical information, and cleartext transmission of sensitive data—reflect the challenges of maintaining cryptographic assurance and user awareness in a client-side encryption tool. Defenders should track this vendor's releases closely given the security-sensitive nature of its product, even within a modest disclosure volume; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 38% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cryptomator over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2022
4 years ago
Most Recent CVE
Apr 16, 2026
99 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-32309HIGH
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vaul
Mar 20, 20267.527NONO
CVE-2026-32303MEDIUM
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, an integrity check vulnerability allows an attacker to tamper with the vault configuration
Mar 20, 20265.923NONO
CVE-2026-32318MEDIUM
Cryptomator for IOS offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 2.8.3, an integrity check vulnerability allows an attacker tam
Mar 20, 20265.922NONO
CVE-2026-32317MEDIUM
Cryptomator for Android offers multi-platform transparent client-side encryption for files in the cloud. Prior to version 1.12.3, an integrity check vulnerability allows an attacke
Mar 20, 20265.922NONO
CVE-2023-39520HIGH
Cryptomator encrypts data being stored on cloud infrastructure. The MSI installer provided on the homepage for Cryptomator version 1.9.2 allows local privilege escalation for low p
Aug 7, 20237.822NONO
CVE-2023-37907HIGH
Cryptomator is data encryption software for users who store their files in the cloud. Prior to version 1.9.2, the MSI installer provided on the homepage allows local privilege esca
Jul 25, 20237.821NONO
CVE-2026-32310MEDIUM
Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the
Mar 20, 20265.320NONO
CVE-2022-25366HIGH
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for Hardened Runtime, it has the com.apple.security.cs.disable-library-validation and com.
Feb 19, 20227.820NONO
CVE-2026-33472MEDIUM
Cryptomator is an open-source client-side encryption application for cloud storage. Version 1.19.1 contains a logic flaw in CheckHostTrustController.getAuthority() that allows an a
Apr 16, 20264.819NONO
CVE-2026-29110MEDIUM
Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.0, in non-debug mode Cryptomator might leak cleartext paths into the log file. This can reveal
Mar 6, 20265.318NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
40%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (30.0%)
Network7 (70.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (60.0%)
High4 (40.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low7 (70.0%)
High0 (0.0%)
None3 (30.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cryptomator.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cryptomator — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cryptomator's Products

View all 2 CNAs →

Top CWEs