CVE-2019-16371: Logmein Lastpass

High severity, CVSS 8.2. EPSS: 1.2% chance of exploitation in the next 30 days.

LogMeIn LastPass before 4.33.0 allows attackers to construct a crafted web site that captures the credentials for a victim's account on a previously visited web site, because do_popupregister can be bypassed via clickjacking.

Affected products

  • Logmein Lastpass: before 4.33.0 (fixed in 4.33.0)

Published 2019-09-16. Last modified 2026-06-17.