SB2026092266 - Multiple vulnerabilities in TeamPass
Published: September 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 16 vulnerabilities.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to a client-side output sanitization bypass in the item-description preview renderer when rendering stored item descriptions. A remote attacker can store crafted markup in an item description to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
2) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to a client-side output sanitization bypass in the item search-results renderer when rendering stored item labels, descriptions, or folder names. A remote attacker can store crafted markup in searchable item data to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
3) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to a client-side output sanitization bypass in the per-user visible-folders renderer when rendering stored folder titles. A remote attacker can store crafted markup in a folder title to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper encoding for a JSON string context in the background-task log table renderer when rendering stored display values. A remote attacker can store crafted markup in a background-task display value to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
5) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper encoding for a JSON string context in the send-email task log table renderer when rendering recipient names. A remote attacker can store crafted markup in a recipient name to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
6) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper encoding for a JSON string context in the finished-task table renderer when rendering stored item labels. A remote attacker can store crafted markup in an item label to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
7) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper encoding for a JSON string context in the item log table renderer when rendering stored item labels. A remote attacker can store crafted markup in an item label to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
8) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the Connections log renderer when rendering escaped user identity fields. A remote attacker can store crafted markup in a user identity field to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
9) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper validation of proxy headers and improper output encoding in the failed-login log renderer when processing a failed login request. A remote attacker can send a failed login request with crafted proxy-header data to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the failed-login log.
10) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the subfolder list renderer when rendering stored folder titles. A remote attacker can store crafted markup in a folder title to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
11) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the per-user folder-rights role badge renderer when rendering stored role titles. A remote attacker can store crafted markup in a role title to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
12) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the transparent-recovery statistics modal when rendering stored event login values. A remote attacker can store crafted markup in an event login value to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected modal.
13) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the item-deleted WebSocket toast renderer when handling item-deleted events. A remote attacker can cause a crafted item label to be rendered in a WebSocket toast to execute arbitrary JavaScript in another user's browser.
User interaction is required to receive the affected event.
14) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the backup administration list renderer when rendering backup metadata. A remote attacker can provide crafted backup metadata to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
15) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper output encoding in the item list icon renderer when rendering API-controlled icon values in an HTML attribute. A remote attacker can supply a crafted icon value through the API to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the affected view.
16) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to improper neutralization of JavaScript line terminators in the items page script when rendering the session language in a JavaScript comment. A remote attacker can store a crafted session language value to execute arbitrary JavaScript in another user's browser.
User interaction is required to open the items page.
Remediation
Install update from vendor's website.