CVE-2018-10193: Logmein Lastpass
High severity, CVSS 7.5. EPSS: 4.7% chance of exploitation in the next 30 days.
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.
Affected products
- Logmein Lastpass: up to and including 4.15.0
Published 2018-04-18. Last modified 2026-06-17.