CVE-2015-8378: Keepassx Project Keepassx

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

In KeePassX before 0.4.4, a cleartext copy of password data is created upon a cancel of an XML export action. This allows context-dependent attackers to obtain sensitive information by reading the .xml dotfile.

Affected products

Published 2017-04-10. Last modified 2026-06-17.