<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – PrivateBin</title>
  <link>https://cvedaily.com/pages/tags/privatebin.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/privatebin.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – PrivateBin</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:04 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2025-64714 – PrivateBin is an online pastebin where the server has zero knowledge of pasted d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64714</guid>
    <pubDate>Thu, 13 Nov 2025 16:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64714</strong></p>
  <p>PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion exists in the template-switching feature. If `templateselection` is enabled in the configuration, the server trusts the `template` cookie and includes the referenced PHP file. An attacker can read sensitive data or, if t…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-64711 – PrivateBin is an online pastebin where the server has zero knowledge of pasted d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64711</guid>
    <pubDate>Thu, 13 Nov 2025 03:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-64711</strong></p>
  <p>PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, dragging a file whose filename contains HTML is reflected verbatim into the page via the drag-and-drop helper, so any user who drops a crafted file on PrivateBin will execute arbitrary JavaScript within their own session (self-XSS). This allows an attacker who…</p>
  <p><strong>CVSS:</strong> 3.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-62796 – PrivateBin is an online pastebin where the server has zero knowledge of pasted d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62796</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62796</guid>
    <pubDate>Tue, 28 Oct 2025 21:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-62796</strong></p>
  <p>PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Versions 1.7.7 through 2.0.1 allow persistent HTML injection via the unsanitized attachment filename (attachment_name) when attachments are enabled. An attacker can modify attachment_name before encryption so that, after decryption, arbitrary HTML is inserted unescaped into the page near the file size hint, enabl…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62796">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-39899 – PrivateBin is an online pastebin where the server has zero knowledge of pasted d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39899</guid>
    <pubDate>Tue, 09 Jul 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-39899</strong></p>
  <p>PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was to allow using the YOURLs URL shortener without running the YOURLs instance without authentication and/or exposing the authentication token to the public, allowing anyone to shorten any URL. With the proxy mechanism, anyone can shorten any…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24833 – PrivateBin is minimalist, open source online pastebin clone where the server has...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24833</guid>
    <pubDate>Mon, 11 Apr 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24833</strong></p>
  <p>PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the time still called ZeroBin. The issue is caused by the fact that SVGs can contain JavaScript. This can allow an attacker t…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24833">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5223 – In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5223</guid>
    <pubDate>Thu, 23 Jan 2020 02:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5223</strong></p>
  <p>In PrivateBin versions 1.2.0 before 1.2.2, and 1.3.0 before 1.3.2, a persistent XSS attack is possible. Under certain conditions, a user provided attachment file name can inject HTML leading to a persistent Cross-site scripting (XSS) vulnerability. The vulnerability has been fixed in PrivateBin v1.3.2 & v1.2.2. Admins are urged to upgrade to these versions to protect the affected users.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5223">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
