Skip to main content

Vendor archive

keepassxc CVEs

Beta · best-effort

4 CVEs tagged to vendor keepassxc0 Critical, 1 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2025-65203

Published Dec 17, 2025

KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowin…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-33901

Published May 20, 2024

Issue in KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover some passwords stored in the .kdbx database via a memory dump. NOTE: the vendor dispu…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-33900

Published May 20, 2024

KeePassXC 2.7.7 allows an attacker (who has the privileges of the victim) to recover cleartext credentials via a memory dump. NOTE: the vendor disputes this because memory-managem…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-35866

Published Jun 19, 2023

In KeePassXC through 2.7.5, a local attacker can make changes to the Database security settings, including master password and second-factor authentication, within an authenticate…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1