CVE-2026-3107Disclosure(teampass / teampass)

LOWCVSS 5.4 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Stored Cross-Site Scripting (XSS) in Teampass versions prior to 3.1.5.16, affecting the password manager's password import functionality at the endpoint 'redacted/index.php?page=items'. The application fails to properly sanitize and encode user-input data during the import process, allowing malicious JavaScript payloads to be persistently stored in the database. When other users view the imported passwords, the payload is automatically executed in their browsers, resulting in a stored XSS condition at the endpoint 'redacted/index.php?page=items'. Exploiting this vulnerability allows an attacker to execute arbitrary JavaScript code in the context of multiple users and the administrator, which can lead to session hijacking, credential theft, privilege abuse, and compromise of application integrity.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • teampass

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
teampass

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-31: 203-31
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
Full discourse2 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️ #INCIBEaviso | Múltiples vulnerabilidades en #Teampass #CVE CVE-2026-3106 y CVE-2026-3107 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-teampass #AvisosDeSeguridad #TI #CNA #0day

    Post summary

    INCIBE has issued a security alert about two new CVEs (CVE-2026-3106 and CVE-2026-3107) affecting Teampass. No additional exploit details, patches, or active exploitation reports are provided.

    02050437
    42.6K followersView on X
  • Autumn Good@autumn_good_35
    General

    🚨🚨🚨 CVE-2026-3106 CVE-2026-3107 Múltiples vulnerabilidades en Teampass | INCIBE-CERT https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-teampass

    Post summary

    A brief alert listing CVE-2026-3106 and CVE-2026-3107 with a link to an INCIBE CERT page, lacking detailed technical information or exploitation details.

    00000283
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appteampassteampass---

Explore more