Passbolt is a password-management platform centered on its API server and browser-extension components, deployed in organizations requiring collaborative credential governance. Its vulnerability profile reflects web-application and information-disclosure patterns inherent to credential-handling software, with recurring exposures in cross-site scripting, sensitive-information disclosure, and reliance on less-trusted data sources. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Passbolt over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27913HIGH Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name | Mar 10, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-33669MEDIUM An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information | Apr 26, 2024 | 6.8 | 20 | NO | NO |
CVE-2017-1000442MEDIUM Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace | Jan 2, 2018 | 5.4 | 20 | NO | NO |
CVE-2024-33670MEDIUM Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is | Apr 26, 2024 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Passbolt.
Media articles that mention a CVE ID that affects a product developed by Passbolt — matched by CVE ID, not by vendor name.