PrivateBin is a minimalist, self-hosted pastebin application designed for secure ephemeral message sharing, and its vulnerability profile centers on the single PrivateBin product itself. Observed weaknesses cluster around cross-site scripting in web page generation, a class endemic to client-side content handling in web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Privatebin over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24833MEDIUM PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability wa | Apr 11, 2022 | 6.1 | 21 | NO | NO |
CVE-2025-64711MEDIUM PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, dragging a file whose filename contains H | Nov 13, 2025 | 5.4 | 19 | NO | NO |
CVE-2020-5223MEDIUM In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain conditions, a user provided attachment file name can inject HT | Jan 23, 2020 | 4.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Privatebin.
Media articles that mention a CVE ID that affects a product developed by Privatebin — matched by CVE ID, not by vendor name.