All 6 CVE vulnerabilities found in PrivateBin, with AI-generated Chinese analysis, references, and POCs.
Vendor: PrivateBin
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-64714 | PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal CWE-23 | 5.8 | Medium | 2025-11-13 |
| CVE-2025-64711 | PrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for users CWE-79 | 3.9 | Low | 2025-11-13 |
| CVE-2025-62796 | PrivateBin persistent HTML injection in attachment filename enables redirect and defacement CWE-79 | 5.8 | Medium | 2025-10-28 |
| CVE-2024-39899 | PrivateBin allows shortening of URLs for other domains CWE-305 | 5.3 | Medium | 2024-07-09 |
| CVE-2022-24833 | Persistent Cross-site Scripting (XSS) vulnerability in PrivateBin CWE-79 | 8.2 | High | 2022-04-11 |
| CVE-2020-5223 | Persistent XSS vulnerability in filename of attached file in PrivateBin CWE-79 | 6.1 | Medium | 2020-01-23 |
All 6 known CVE vulnerabilities affecting PrivateBin with full Chinese analysis, references, and POCs where available.