PT-2026-29213 · Teampass · Teampass
Published
2026-03-31
·
Updated
2026-03-31
·
CVE-2026-3107
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Teampass versions prior to 3.1.5.16
Description
A stored Cross-Site Scripting (XSS) issue exists in Teampass affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application does not properly sanitize and encode user-input data during the import process, allowing malicious JavaScript payloads to be persistently stored in the database. When other users view the imported passwords, the payload is automatically executed in their browsers, resulting in a stored XSS condition at the endpoint 'redacted/index.php?page=items'. Exploiting this issue allows an attacker to execute arbitrary JavaScript code in the context of multiple users and the administrator, potentially leading to session hijacking, credential theft, and compromise of application integrity.
Recommendations
Update Teampass to version 3.1.5.16 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teampass