📦 Syspass

by Syspass

🔍 What is Syspass?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-25477

HIGH CVSS 8.1 Feb 28, 2025

A host header injection vulnerability in SysPass 3.2x allows attackers to inject malicious JavaScript from arbitrary domains, which executes in victims' browsers when they access the vulnerable applic...

CVE-2025-25478

MEDIUM CVSS 6.5 Feb 28, 2025

This vulnerability in Syspass 3.2.x allows attackers to access the web application's source code by exploiting improper filename handling in the account file upload feature. This can expose sensitive ...

CVE-2024-42904

MEDIUM CVSS 6.1 Sep 3, 2024

This cross-site scripting (XSS) vulnerability in SysPass 3.2.x allows attackers to inject malicious scripts into the client name parameter, which could execute arbitrary JavaScript in users' browsers....