Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Syspass

First CVE: Mar 6, 2017Active for: 9 yearsTotal CVEs: 7

Syspass is a self-hosted password management and credential storage application with a focused but security-sensitive deployment footprint. Its vulnerability profile reflects the input-handling and data-protection demands of a secrets-management tool, centered on cross-site scripting, file-path manipulation, injection flaws, and inadequate encryption strength—weaknesses that could expose stored credentials or enable unauthorized access to the credential vault. Defenders deploying this application should prioritize network segmentation, access controls, and timely patching; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Syspass over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2017
9 years ago
Most Recent CVE
Feb 28, 2025
511 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-25477HIGH
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.
Feb 28, 20258.123NONO
CVE-2017-9306MEDIUM
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" sub
May 31, 20176.121NONO
CVE-2025-25478MEDIUM
The account file upload functionality in Syspass 3.2.x fails to properly handle special characters in filenames. This mismanagement leads to the disclosure of the web application s
Feb 28, 20256.520NONO
CVE-2024-42904MEDIUM
A cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the name parameter at /Co
Sep 3, 20246.119NONO
CVE-2022-4930MEDIUM
A vulnerability classified as problematic was found in nuxsmin sysPass up to 3.2.4. Affected by this vulnerability is an unknown functionality of the component URL Handler. The man
Mar 6, 20235.419NONO
CVE-2017-5999HIGH
An issue was discovered in sysPass 2.x before 2.1, in which an algorithm was never sufficiently reviewed by cryptographers. The fact that inc/SP/Core/Crypt.class is using the MCRYP
Mar 6, 20177.519NONO
CVE-2025-25476MEDIUM
A stored cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows a malicious user with elevated privileges to execute arbitrary Javascript code by specifying a malicious X
Feb 28, 20255.417NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
71%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (28.6%)
Unknown0 (0.0%)
Required5 (71.4%)
Privileges Required
Low3 (42.9%)
High0 (0.0%)
None4 (57.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Syspass.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Syspass — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Syspass's Products

View all 2 CNAs →

Top CWEs