Dropbox's vulnerability profile centers on a focused set of cloud-storage, synchronization, and SDK products that serve a broad user base, with exposure spanning both the core desktop application and downstream integrations through its developer tooling. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including improper authentication, out-of-bounds writes, and cleartext storage of sensitive information—issues characteristic of client-side data-handling and credential-management logic. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dropbox over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4768CRITICAL A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Publi | Dec 27, 2022 | 9.8 | 29 | NO | NO |
CVE-2024-5924HIGH Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected insta | Jun 13, 2024 | 8.8 | 25 | NO | NO |
CVE-2022-26181HIGH Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108. | Feb 28, 2022 | 7.8 | 25 | NO | NO |
CVE-2024-25718CRITICAL In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a | Feb 11, 2024 | 9.8 | 24 | NO | NO |
CVE-2019-12171HIGH Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account | Jul 8, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-20819HIGH io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or pos | Apr 23, 2019 | 7.8 | 24 | NO | NO |
CVE-2017-7448MEDIUM The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and appli | Apr 5, 2017 | 5.5 | 21 | NO | NO |
CVE-2026-28809MEDIUM XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML docum | Mar 23, 2026 | 5.3 | 20 | NO | NO |
CVE-2018-12271MEDIUM An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LACon | Jun 13, 2018 | 6.4 | 20 | NO | NO |
CVE-2017-8891MEDIUM Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads. | May 10, 2017 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dropbox.
Media articles that mention a CVE ID that affects a product developed by Dropbox — matched by CVE ID, not by vendor name.