Cryptpad
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Cryptpad, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Cryptpad CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 2 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium4
Latest CVEs
The 6 most recently published vulnerabilities affecting Cryptpad.
- CVE-2026-26028CryptPad: Sanitizer Bypass in Diffmarked.js Allows Arbitrary HTML Injection and Potential XSS6.1
- CVE-2025-51846CryptPad unbounded WebSocket frame flood7.5
- CVE-2025-49591CryptPad 2FA Bypass Vulnerability9.1
- CVE-2025-49590CryptPad Dom-Based Cross-Site Scripting (XSS) Vulnerability6.1
- CVE-2019-15302The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a...6.5
- CVE-2017-1000051Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content6.1
Product grouping is registry-driven, with AI assist and human review. How it works