Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dropbox

First CVE: Oct 20, 2010Active for: 16 yearsTotal CVEs: 16
16.8
VTI Score
Low

Dropbox's vulnerability profile centers on a focused set of cloud-storage, synchronization, and SDK products that serve a broad user base, with exposure spanning both the core desktop application and downstream integrations through its developer tooling. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including improper authentication, out-of-bounds writes, and cleartext storage of sensitive information—issues characteristic of client-side data-handling and credential-management logic. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dropbox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2010
15 years ago
Most Recent CVE
Mar 23, 2026
123 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-4768CRITICAL
A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Publi
Dec 27, 20229.829NONO
CVE-2024-5924HIGH
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected insta
Jun 13, 20248.825NONO
CVE-2022-26181HIGH
Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.
Feb 28, 20227.825NONO
CVE-2024-25718CRITICAL
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a
Feb 11, 20249.824NONO
CVE-2019-12171HIGH
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account
Jul 8, 20197.824NONO
CVE-2018-20819HIGH
io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or pos
Apr 23, 20197.824NONO
CVE-2017-7448MEDIUM
The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and appli
Apr 5, 20175.521NONO
CVE-2026-28809MEDIUM
XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML docum
Mar 23, 20265.320NONO
CVE-2018-12271MEDIUM
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LACon
Jun 13, 20186.420NONO
CVE-2017-8891MEDIUM
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.
May 10, 20175.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
13%
50%
25%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (50.0%)
Network5 (31.3%)
Unknown1 (6.3%)
Physical2 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (68.8%)
High4 (25.0%)
Unknown1 (6.3%)
User Interaction
None6 (37.5%)
Unknown1 (6.3%)
Required9 (56.3%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None14 (87.5%)
Unknown1 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dropbox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dropbox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dropbox's Products

View all 5 CNAs →

Top CWEs