Dani-garcia

Vaultwarden

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 04.03.2026 21:44:45
  • Zuletzt bearbeitet 04.03.2026 22:16:18

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though...

  • EPSS -
  • Veröffentlicht 04.03.2026 21:40:33
  • Zuletzt bearbeitet 04.03.2026 22:16:18

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as...

  • EPSS -
  • Veröffentlicht 04.03.2026 21:34:34
  • Zuletzt bearbeitet 04.03.2026 22:16:18

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, there is a privilege escalation vulnerability via bulk permission update to unauthorized collections by Manager. This i...

  • EPSS -
  • Veröffentlicht 04.03.2026 21:32:14
  • Zuletzt bearbeitet 04.03.2026 22:16:17

Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Vaultwarden versions 1.34.3 and prior are susceptible to a 2FA bypass when performing protected actions. An attacker who gains authenticated acc...

  • EPSS 0.01%
  • Veröffentlicht 11.02.2026 21:14:58
  • Zuletzt bearbeitet 13.02.2026 21:41:01

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to 1.35.3, a regular organization member can retrieve all ciphers within an organization, regardless of collection permissions. The endpoi...

Exploit
  • EPSS 2.16%
  • Veröffentlicht 27.01.2025 18:15:41
  • Zuletzt bearbeitet 20.08.2025 14:16:53

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then change some ...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 27.01.2025 18:15:41
  • Zuletzt bearbeitet 20.08.2025 13:56:46

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker can obtain owner rights of other organization. Hacker should know the ID of victim organization (in real case the user can be a part of...

  • EPSS 0.07%
  • Veröffentlicht 20.12.2024 21:15:10
  • Zuletzt bearbeitet 19.08.2025 13:46:58

vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. In affected versions an attacker is capable of updating or deleting groups from an organization given a few conditions: 1. The attacker has a us...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 13.09.2024 18:15:04
  • Zuletzt bearbeitet 10.07.2025 13:22:41

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated a...

  • EPSS 0.25%
  • Veröffentlicht 13.09.2024 18:15:03
  • Zuletzt bearbeitet 10.07.2025 13:23:50

An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A vulnerability has been identified in the authentication and authorization process of the endpoint responsible for altering the metadata of an emergency access. It permits an att...