cbcvebase.

Dani-Garcia Vaultwarden vulnerabilities

25 known vulnerabilities affecting dani-garcia/vaultwarden.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH12MEDIUM10

Vulnerabilities

Page 2 of 2
CVE-2026-31835P4MEDIUMCVSS 5.4fixed in 1.35.52026-05-05
CVE-2026-31835 [MEDIUM] CWE-345 CVE-2026-31835: Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the We Vaultwarden is a Bitwarden-compatible server written in Rust. In versions 1.35.4 and earlier, the WebAuthn authentication flow in `validate_webauthn_login()` updates persistent credential metadata (1backup_eligible1 and 1backup_state flags1) based on unverified `authenticatorData` before signature validation is performed. An attacker who knows a use
nvd
CVE-2026-27898P4MEDIUMCVSS 5.4fixed in 1.35.42026-03-04
CVE-2026-27898 [MEDIUM] CWE-639 CVE-2026-27898: Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarde Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, an authenticated regular user can specify another user’s cipher_id and call "PUT /api/ciphers/{id}/partial" Even though the standard retrieval API correctly denies access to that cipher, the partial update endpoint retur
ghsanvdosv
CVE-2026-33420P4MEDIUMCVSS 5.3fixed in 1.35.52026-05-05
CVE-2026-33420 [MEDIUM] CWE-862 CVE-2026-33420: Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing the has_full_access() authorization check that exists on the sibling get_org_collections endpoint. This allows any Manager-role user with accessAll=Fals
nvd
CVE-2024-39926P4MEDIUMCVSS 5.4v1.30.32024-09-13
CVE-2024-39926 [MEDIUM] CWE-79 CVE-2024-39926: An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting An issue was discovered in Vaultwarden (formerly Bitwarden_RS) 1.30.3. A stored cross-site scripting (XSS) or, due to the default CSP, HTML injection vulnerability has been discovered in the admin dashboard. This potentially allows an authenticated attacker to inject malicious code into the dashboard, which is then executed or rendered in the context
nvd
CVE-2024-55226P4MEDIUMCVSS 5.4v1.32.52025-01-09
CVE-2024-55226 [MEDIUM] CWE-79 CVE-2024-55226: Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
ghsanvdosv
Dani-Garcia Vaultwarden vulnerabilities | cvebase