🔐 CVE Alert

CVE-2026-3106

UNKNOWN 0.0

Multiple vulnerabilities in Teampass

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
15th

Blind Cross-Site Scripting (XSS) in Teampass, versions prior to 3.1.5.16, within the password manager login functionality in the 'contraseña' parameter of the login form 'redacted/index.php'. During failed authentication attempts, the application does not properly clean or encode the information entered by the user in the username field. As a result, arbitrary JavaScript code is automatically executed in the administrator's browser when viewing failed login entries, resulting in a blind XSS condition.

CWE CWE-79
Vendor teampass
Product teampass
Published Mar 31, 2026
Last Updated Mar 31, 2026
Stay Ahead of the Next One

Get instant alerts for teampass teampass

Be the first to know when new unknown vulnerabilities affecting teampass teampass are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Teampass / Teampass
0 ≤ 3.1.5.16

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-teampass

Credits

Julen Garrido Estévez (B3xal)