KeePass is a widely trusted password manager whose vulnerability profile, despite a narrow product scope, reflects the security-critical nature of credential storage and transmission. The recurring weaknesses center on sensitive-data handling: cleartext storage and transmission of passwords, improper input validation, and unintended information exposure—issues inherent to applications that manage authentication material. Defenders should prioritize KeePass updates and review deployment practices around credential vault protection and network exposure; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keepass over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32784HIGH In KeePass 2.x before 2.54, it is possible to recover the cleartext master password from a memory dump, even when a workspace is locked or no longer running. The memory dump can be | May 15, 2023 | 7.5 | 28 | NO | NO |
CVE-2016-5119HIGH The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted | Jan 23, 2017 | 7.5 | 26 | NO | NO |
CVE-2019-20184HIGH KeePass 2.4.1 allows CSV injection in the title field of a CSV export. | Jan 9, 2020 | 7.8 | 24 | NO | NO |
CVE-2023-24055MEDIUM KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigg | Jan 22, 2023 | 5.5 | 22 | NO | NO |
CVE-2022-0725HIGH A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an | Mar 10, 2022 | 7.5 | 22 | NO | NO |
CVE-2017-1000066HIGH The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information. | Jul 17, 2017 | 7.5 | 22 | NO | NO |
CVE-2010-5200MEDIUM Untrusted search path vulnerability in KeePass Password Safe before 1.18 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstra | Sep 6, 2012 | 6.9 | 21 | NO | NO |
CVE-2010-5196MEDIUM Untrusted search path vulnerability in KeePass Password Safe before 2.13 allows local users to gain privileges via a Trojan horse DwmApi.dll file in the current working directory, | Sep 6, 2012 | 6.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keepass.
Media articles that mention a CVE ID that affects a product developed by Keepass — matched by CVE ID, not by vendor name.