Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Passbolt/
  3. PassBolt

PassBolt

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 25/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 4 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

An open-source credential management platform that provides end-to-end encrypted password sharing and storage capabilities for organizations.

by Passbolt · passbolt.com · source ↗

Known CVEs (4)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-27913 ↗HIGH 7.52025

    Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attack…

  • CVE-2024-33670 ↗MEDIUM 4.32024

    Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the crafted URL. Although the injected content is not executed as Jav…

  • CVE-2024-33669 ↗MEDIUM 6.12024

    An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak. This allows a…

  • CVE-2017-1000442 ↗MEDIUM 5.42018

    Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace

Materials

1

Datasheets

  • Security White Paper Passbolt Pro Edition V5.10 (March 2026 Rev10) ↗

Other Password Management products

see all →
  • 1Password Enterprise Password Manager · 1Password
  • 1Password Enterprise Password Manager - MSP Edition · 1Password
  • 1Password Password Manager · 1Password
  • 1Password Teams Starter Pack · 1Password
  • Akeyless Password Manager · Akeyless Security
  • Avatier Password Bouncer · Avatier
  • Avira Password Manager · Avira
  • Bitwarden Enterprise · Bitwarden