PT-2026-29213 · Teampass · Teampass

Published

2026-03-31

·

Updated

2026-03-31

·

CVE-2026-3107

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Teampass versions prior to 3.1.5.16
Description A stored Cross-Site Scripting (XSS) issue exists in Teampass affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application does not properly sanitize and encode user-input data during the import process, allowing malicious JavaScript payloads to be persistently stored in the database. When other users view the imported passwords, the payload is automatically executed in their browsers, resulting in a stored XSS condition at the endpoint 'redacted/index.php?page=items'. Exploiting this issue allows an attacker to execute arbitrary JavaScript code in the context of multiple users and the administrator, potentially leading to session hijacking, credential theft, and compromise of application integrity.
Recommendations Update Teampass to version 3.1.5.16 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3107

Affected Products

Teampass