Bounties
Partners
Community
Info
nilsteampassnet / teampass
Project repository
Collaborative Passwords Manager
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
24 DAYS
FIX
WITHIN
21 DAYS
Stored XSS at Search page
Jul 6th 2023
tvnnn
•
High
High
•
CVE-2023-3531
CVE-2023-3531
Improper handling of input value leads to Remote Code Execution or Denial of Ser...
Jul 8th 2023
hiu240900
•
Critical
Critical
•
CVE-2023-3551
CVE-2023-3551
XSS Filter Bypass in Folder Name leading to Information Disclosure
Jul 8th 2023
jayesther
•
High
High
•
CVE-2023-3552
CVE-2023-3552
Directory listing in multiple endpoints
Jul 8th 2023
nerrorsec
•
Medium
Medium
•
CVE-2023-3553
CVE-2023-3553
Stored XSS via Default session expiration time
Jul 8th 2023
nerrorsec
•
Medium
Medium
•
CVE-2023-3565
CVE-2023-3565
Stored XSS via Custom Login Message
Jul 8th 2023
nerrorsec
•
informative
Medium
Stored-Cross Site Scripting (XSS) in Duo Security Configuration
Aug 17th 2023
sahiloj
•
not applicable
Cross Site Scripting (XSS) in Adding New API Key Feature
Jun 10th 2023
sahiloj
•
pending
Stored-Cross Site Scripting (XSS) in Add New Role Feature
Jun 10th 2023
sahiloj
•
pending
HTML Injection in Folder Name
Jun 10th 2023
nerrorsec
•
Low
Low
•
CVE-2023-3190
CVE-2023-3190
Stored XSS in many configuration fields
Jun 10th 2023
tvnnn
•
High
High
•
CVE-2023-3191
CVE-2023-3191
Stored XSS on user's name
Jun 3rd 2023
tvnnn
•
Medium
Medium
•
CVE-2023-3083
CVE-2023-3083
Browser back attack vulnerability in nilsteampassnet / teampass
May 30th 2023
newb3ast
•
pending
Stored XSS on item name - Bypass of (CVE-2023-2516)
May 31st 2023
mnqazi
•
High
High
•
CVE-2023-3009
CVE-2023-3009
Stored XSS on FolderName Affecting other users and admin.
Jun 3rd 2023
srivallikusumba
•
High
High
•
CVE-2023-3084
CVE-2023-3084
Stored XSS on items in Folder in nilsteampassnet/teampass lead to ATO
Jun 3rd 2023
tadjmen
•
Critical
Critical
•
CVE-2023-3086
CVE-2023-3086
Stored HTML injection in folderName affecting Admin
May 24th 2023
mnqazi
•
High
High
•
CVE-2023-2859
CVE-2023-2859
Stored HTML Injection in Item Label
May 9th 2023
mnqazi
•
High
High
•
CVE-2023-2591
CVE-2023-2591
Stored XSS on items in Folder
May 4th 2023
mnqazi
•
Medium
Medium
•
CVE-2023-2516
CVE-2023-2516
Broken Access Control On Item via ID
Jun 4th 2023
tht1997
•
Medium
Medium
•
CVE-2023-3095
CVE-2023-3095
Stored XSS on function item with folder
Apr 13th 2023
tht1997
•
Medium
Medium
•
CVE-2023-2021
CVE-2023-2021
IDOR Vulnerability Allow Low-Level User Logout Everyone Includes Admin
Mar 17th 2023
choocs
•
Medium
Medium
•
CVE-2023-1463
CVE-2023-1463
Arbitrary txt files deletion (authenticated)
Feb 27th 2023
zonia3000
•
High
High
•
CVE-2023-1070
CVE-2023-1070
SQL injection in API authorization check
Mar 21st 2023
zonia3000
•
High
High
•
CVE-2023-1545
CVE-2023-1545
CRITICAL
$0
HIGH
$0
MEDIUM
$0
LOW
$0