Teampass is a modestly represented, narrowly scoped password-management and credential-sharing platform that occupies a high-value position in organizational access control infrastructure. The vendor's vulnerability profile concentrates in a single product and is characterized by a recurring pattern of web-layer input handling and privilege-management flaws, including cross-site scripting, SQL injection, code injection, and improper output encoding—weaknesses endemic to web applications handling sensitive data. These vulnerabilities frequently acquire public exploit code, reflecting the appeal of credential-management systems as targets for post-authentication lateral movement and privilege escalation. Defenders should treat Teampass disclosures as high-priority given the product's role in managing organizational secrets and apply patches promptly; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teampass over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1545HIGH SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23. | Mar 21, 2023 | 7.5 | 39 | NO | YES |
CVE-2015-7564CRITICAL Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon a | Apr 12, 2017 | 9.8 | 35 | NO | YES |
CVE-2015-7563HIGH Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user. | Apr 12, 2017 | 8.8 | 35 | NO | YES |
CVE-2020-12478HIGH TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files. | Apr 29, 2020 | 7.5 | 31 | NO | YES |
CVE-2023-3086CRITICAL Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | Jun 3, 2023 | 9.0 | 29 | NO | NO |
CVE-2017-9436CRITICAL TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php. | Jun 5, 2017 | 9.8 | 29 | NO | NO |
CVE-2020-12479HIGH TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory t | Apr 29, 2020 | 8.8 | 28 | NO | NO |
CVE-2019-1000001CRITICAL TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recover | Feb 4, 2019 | 9.8 | 28 | NO | NO |
CVE-2023-2859HIGH Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9. | May 24, 2023 | 8.8 | 26 | NO | NO |
CVE-2017-15055HIGH TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled | Nov 27, 2017 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teampass.
Media articles that mention a CVE ID that affects a product developed by Teampass — matched by CVE ID, not by vendor name.