« Back to list

Xwiki

Xwiki Cryptpad: vulnerabilities and CVEs

Xwiki Cryptpad has 6 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-26028Medium (6.1)0.29%—May 20, 2026
CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer…
CVE-2025-51846High (8.7)0.58%—Apr 30, 2026
CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
CVE-2025-49591High (7.4)0.52%—Jun 18, 2025
CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that…
CVE-2025-49590Low (2.9)0.33%—Jun 18, 2025
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early…
CVE-2019-15302Medium (6.5)1.4%—Sep 11, 2019
The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL…
CVE-2017-1000051Medium (6.1)1.2%—Jul 17, 2017
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content

🎯 How it gets exploited (ATT&CK techniques)

  1. T1078 Valid Accounts1
  2. T1190 Exploit Public-Facing Application1
  3. T1210 Exploitation of Remote Services1
  4. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Xwiki