KeePassXC is a password manager and browser-integration toolkit with a focused product scope centered on credential storage and autofill functionality. Its observed vulnerability surface reflects the security-critical nature of that role, with recurring exposure around cleartext-in-memory handling, cross-site request forgery in the browser extension, and authorization and integrity-validation gaps. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keepassxc over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65203HIGH KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing | Dec 17, 2025 | 7.1 | 23 | NO | NO |
CVE-2023-35866MEDIUM In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticated | Jun 19, 2023 | 5.5 | 20 | NO | NO |
CVE-2024-33901MEDIUM Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor disput | May 20, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-33900MEDIUM KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-manageme | May 20, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keepassxc.
Media articles that mention a CVE ID that affects a product developed by Keepassxc — matched by CVE ID, not by vendor name.