Xwiki Cryptpad
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Xwiki Cryptpad.
By the Year
In 2026 there have been 0 vulnerabilities in Xwiki Cryptpad. Last year, in 2025 Cryptpad had 2 security vulnerabilities published. Right now, Cryptpad is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 2 | 7.60 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 0.00 |
It may take a day or so for new Cryptpad vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Xwiki Cryptpad Security Vulnerabilities
CryptPad 2FA bypass via path encoding before 2025.3.0
CVE-2025-49591
9.1 - Critical
- June 18, 2025
CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain access to the victim's account, even if the victim has 2FA set up. This is due to 2FA not being enforced if the path parameter is not 44 characters long, which can be bypassed by simply URL encoding a single character in the path. This issue has been patched in version 2025.3.0.
authentification
CryptPad XSS via Link Bouncer before 2025.3.0
CVE-2025-49590
6.1 - Medium
- June 18, 2025
CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's protocol/scheme is checked, which a maliciously crafted URI can follow. This issue has been patched in version 2025.3.0.
Incomplete Denylist to Cross-Site Scripting
The pad management logic in XWiki labs CryptPad before 3.0.0
CVE-2019-15302
- September 11, 2019
The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Xwiki Cryptpad or by Xwiki? Click the Watch button to subscribe.