Where
-Infinity
0

Bitwarden VaultwardenVaultwarden: CSRF in SSO Authorization Flow

Risk 67
Severity
8.3
First published (updated )

Bitwarden Bitwarden ServerBitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request

Risk 61
Severity
9.3
First published (updated )

Bitwarden Bitwarden ServerBitwarden Server < 2026.5.0 JSON Injection via Webhook Templates

Risk 26
Severity
2.3
First published (updated )

Bitwarden Bitwarden ServerBitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController

Risk 26
Severity
5.3
First published (updated )

Bitwarden Bitwarden ServerBitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint

Risk 49
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Bitwarden Bitwarden ServerBitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key

Risk 62
Severity
8.6
First published (updated )

Bitwarden Bitwarden ServerBitwarden Server < 2026.4.0 Missing Authorization via Provider Clients

Risk 72
Severity
8.9
First published (updated )

Bitwarden Bitwarden ServerBitwarden Server < 2026.4.1 Missing Authorization via Organization Cipher Import

Risk 34
Severity
5.3
First published (updated )

npm/bitwarden-cliOS Command Injection, Code Injection

Risk 86
Severity
8.8
First published (updated )

The RegisterYou probably can't trust your password manager if it's compromised

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerMajor password managers can leak logins in clickjacking attacks

First published (updated )

Bitwarden BitwardenBitwarden PDF File cross site scripting

Risk 18
Severity
5.1
EPSS
0.03%
First published (updated )

Bitwarden BitwardenBitwarden Desktop 2023.7.0 and below allows an attacker with local access to obtain sensitive inform…

Risk 24
Severity
5.5
EPSS
0.04%
First published (updated )

Bitwarden BitwardenBitwarden Windows desktop application versions prior to v2023.4.0 store biometric keys in Windows Cr…

Risk 52
Severity
7.1
First published (updated )

Bitwarden BitwardenBitwarden through 2023.2.1 offers password auto-fill when the second-level domain matches, e.g., a p…

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Bitwarden BitwardenInfoleak

Risk 43
Severity
7.5
First published (updated )

Bitwarden serverSSRF

Risk 43
Severity
7.5
First published (updated )

Bitwarden serverThe Bitwarden server through 1.32.0 has a potentially unwanted KDF.

Risk 43
Severity
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203