Cryptpad
This hub aggregates every CVE we track for Cryptpad, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
1
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM4HIGH1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
1
1
0
0
0
0
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Cryptpad.
- CVE-2026-26028CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS6.1
- CVE-2025-51846CryptPad unbounded WebSocket frame flood7.5
- CVE-2025-49591CryptPad 2FA Bypass Vulnerability9.1
- CVE-2025-49590CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability6.1
- CVE-2019-15302The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a...6.5
- CVE-2017-1000051Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content6.1
Product normalization is registry-driven with AI assist and human review. How it works