Cryptpad Xwiki Cryptpad

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Xwiki Cryptpad.

By the Year

In 2026 there have been 0 vulnerabilities in Xwiki Cryptpad. Last year, in 2025 Cryptpad had 2 security vulnerabilities published. Right now, Cryptpad is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 2 7.60
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 1 0.00

It may take a day or so for new Cryptpad vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Xwiki Cryptpad Security Vulnerabilities

CryptPad 2FA bypass via path encoding before 2025.3.0
CVE-2025-49591 9.1 - Critical - June 18, 2025

CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain access to the victim's account, even if the victim has 2FA set up. This is due to 2FA not being enforced if the path parameter is not 44 characters long, which can be bypassed by simply URL encoding a single character in the path. This issue has been patched in version 2025.3.0.

authentification

CryptPad XSS via Link Bouncer before 2025.3.0
CVE-2025-49590 6.1 - Medium - June 18, 2025

CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.

Incomplete Denylist to Cross-Site Scripting

The pad management logic in XWiki labs CryptPad before 3.0.0
CVE-2019-15302 - September 11, 2019

The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Xwiki Cryptpad or by Xwiki? Click the Watch button to subscribe.

Xwiki
Vendor

subscribe