Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Logmein

First CVE: Aug 24, 2009Active for: 17 yearsTotal CVEs: 7

Logmein's vulnerability profile centers on remote-access and credential-management platforms, particularly LastPass, which occupy a trusted position in enterprise authentication and access workflows. The recurring weakness classes—improper authentication, insufficiently protected credentials, and uncontrolled resource consumption—reflect the sensitive nature of password vaults and session-management code, and the vendor's disclosures have an elevated tendency toward public exploit availability. Defenders should prioritize tracking this vendor's updates given the downstream trust implications of compromised authentication infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Logmein over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2009
16 years ago
Most Recent CVE
Dec 12, 2020
2,050 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-7053HIGH
LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain lon
Aug 24, 20099.335NOYES
CVE-2019-16371HIGH
LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_po
Sep 16, 20198.226NONO
CVE-2018-10193HIGH
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with
Apr 18, 20187.524NONO
CVE-2020-35208MEDIUM
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The password authentication for unlocking can be bypassed by
Dec 12, 20205.719NONO
CVE-2020-35207MEDIUM
An issue was discovered in the LogMein LastPass Password Manager (aka com.lastpass.ilastpass) app 4.8.11.2403 for iOS. The PIN authentication for unlocking can be bypassed by forci
Dec 12, 20205.719NONO
CVE-2013-5113MEDIUM
LastPass prior to 2.5.1 has an insecure PIN implementation.
Jan 31, 20206.818NONO
CVE-2013-5114MEDIUM
LastPass prior to 2.5.1 allows secure wipe bypass.
Jan 31, 20206.117NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
57%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (28.6%)
Unknown1 (14.3%)
Physical4 (57.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (57.1%)
High2 (28.6%)
Unknown1 (14.3%)
User Interaction
None5 (71.4%)
Unknown1 (14.3%)
Required1 (14.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (85.7%)
Unknown1 (14.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Logmein.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Logmein — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Logmein's Products

View all 1 CNAs →

Top CWEs