Vulnerabilidades em PrivateBin
8 resultadosAnálise Vexday
PrivateBin registra 6 vulnerabilidades históricas na base Vexday, nenhuma delas sob ataque ativo no momento. A fraqueza predominante é Cross-Site Scripting (CWE-79), característica de falhas em validação de entrada web. Sem incidentes críticos recentes ou exploração conhecida, o risco atual é baixo, mas recomenda-se atenção contínua ao padrão de falhas XSS identificado.
CVE-2022-24833HIGHPersistent Cross-site Scripting (XSS) vulnerability in PrivateBinEPSS 1.4%CVE-2020-5223MEDIUMPersistent XSS vulnerability in filename of attached file in PrivateBinEPSS 0.7%CVE-2024-39899MEDIUMPrivateBin allows shortening of URLs for other domainsEPSS 0.6%CVE-2025-64714MEDIUMPrivateBin's template-switching feature allows arbitrary local file inclusion through path traversalEPSS 0.5%CVE-2026-55891NONEPrivateBin: Reflected JSON injection in backend responses via unescaped REQUEST_URIEPSS 0.3%CVE-2025-62796MEDIUMPrivateBin persistent HTML injection in attachment filename enables redirect and defacementEPSS 0.3%CVE-2026-55696MEDIUMPrivateBin: Stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interactionEPSS 0.2%CVE-2025-64711LOWPrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for usersEPSS 0.1%