pkg:crates.io/vaultwarden
7 total CVEsHIGH2MEDIUM1
✅ Check your installed version
All known vulnerabilities
HIGH8.3CVE-2026-27803Vaultwarden's Collection Management Operations Allowed Without `manage` Verification for Manager Role from 0, < 1.35.4
HIGH8.3CVE-2026-27802Vaultwarden has Privilege Escalation via Bulk Permission Update to Unauthorized Collections by Manager from 0, < 1.35.4
MEDIUM5.4CVE-2026-27898Vaultwarden has Unauthorized Access via Partial Update API on Another User’s Cipher from 0, < 1.35.4
—Vaultwarden has 2FA Bypass on Protected Actions due to Faulty Rate Limit Enforcement
from 0, < 1.35.0
—Vaultwarden HTML injection vulnerability
from 0, < 1.32.5
—Vaultwarden authenticated reflected cross-site scripting (XSS) vulnerability
from 0, < 1.32.5
—Vaultwarden vulnerable to user impersonation
from 0, < 1.32.5