CVE-2017-1000442: Passbolt API
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
Affected products
- Passbolt Passbolt API: up to and including 1.6.4
Published 2018-01-02. Last modified 2026-06-17.