Syspass is a self-hosted password management and credential storage application with a focused but security-sensitive deployment footprint. Its vulnerability profile reflects the input-handling and data-protection demands of a secrets-management tool, centered on cross-site scripting, file-path manipulation, injection flaws, and inadequate encryption strength—weaknesses that could expose stored credentials or enable unauthorized access to the credential vault. Defenders deploying this application should prioritize network segmentation, access controls, and timely patching; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syspass over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-25477HIGH A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser. | Feb 28, 2025 | 8.1 | 23 | NO | NO |
CVE-2017-9306MEDIUM inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" sub | May 31, 2017 | 6.1 | 21 | NO | NO |
CVE-2025-25478MEDIUM The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s | Feb 28, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-42904MEDIUM A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Co | Sep 3, 2024 | 6.1 | 19 | NO | NO |
CVE-2022-4930MEDIUM A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an unknown functionality of the component URL Handler. The man | Mar 6, 2023 | 5.4 | 19 | NO | NO |
CVE-2017-5999HIGH An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYP | Mar 6, 2017 | 7.5 | 19 | NO | NO |
CVE-2025-25476MEDIUM A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious X | Feb 28, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syspass.
Media articles that mention a CVE ID that affects a product developed by Syspass — matched by CVE ID, not by vendor name.