Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Teampass

First CVE: Apr 22, 2012Active for: 14 yearsTotal CVEs: 50
41.5
VTI Score
High

Teampass is a modestly represented, narrowly scoped password-management and credential-sharing platform that occupies a high-value position in organizational access control infrastructure. The vendor's vulnerability profile concentrates in a single product and is characterized by a recurring pattern of web-layer input handling and privilege-management flaws, including cross-site scripting, SQL injection, code injection, and improper output encoding—weaknesses endemic to web applications handling sensitive data. These vulnerabilities frequently acquire public exploit code, reflecting the appeal of credential-management systems as targets for post-authentication lateral movement and privilege escalation. Defenders should treat Teampass disclosures as high-priority given the product's role in managing organizational secrets and apply patches promptly; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
5.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Teampass over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2012
14 years ago
Most Recent CVE
Mar 31, 2026
115 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-1545HIGH
SQL Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.0.23.
Mar 21, 20237.539NOYES
CVE-2015-7564CRITICAL
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon a
Apr 12, 20179.835NOYES
CVE-2015-7563HIGH
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.
Apr 12, 20178.835NOYES
CVE-2020-12478HIGH
TeamPass 2.1.27.36 allows an unauthenticated attacker to retrieve files from the TeamPass web root. This may include backups or LDAP debug files.
Apr 29, 20207.531NOYES
CVE-2023-3086CRITICAL
Cross-site Scripting (XSS) - Stored in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
Jun 3, 20239.029NONO
CVE-2017-9436CRITICAL
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.
Jun 5, 20179.829NONO
CVE-2020-12479HIGH
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP request with sources/users.queries.php newValue directory t
Apr 29, 20208.828NONO
CVE-2019-1000001CRITICAL
TeamPass version 2.1.27 and earlier contains a Storing Passwords in a Recoverable Format vulnerability in Shared password vaults that can result in all shared passwords are recover
Feb 4, 20199.828NONO
CVE-2023-2859HIGH
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
May 24, 20238.826NONO
CVE-2017-15055HIGH
TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled
Nov 27, 20178.125NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
56%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network45 (90.0%)
Unknown5 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (88.0%)
High1 (2.0%)
Unknown5 (10.0%)
User Interaction
None20 (40.0%)
Unknown5 (10.0%)
Required25 (50.0%)
Privileges Required
Low28 (56.0%)
High3 (6.0%)
None14 (28.0%)
Unknown5 (10.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.0% of CVEs· 95th percentile
ExploitDB
5 CVEs
10.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Teampass.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Teampass — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Teampass's Products

View all 4 CNAs →

Top CWEs