privatebin/privatebin vulnerabilities
CVEs whose affected-version data names the privatebin/privatebin package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-55891Low· 0.0PrivateBin is an online pastebin where the server has zero knowledge of pasted data
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation …
▾ Sunlitprivatebin · privatebin/privatebinEPSS 0.33%via NVD
CVE-2026-55696Medium· 4.3PrivateBin is an online pastebin where the server has zero knowledge of pasted data
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobU…
▾ Sunlitprivatebin · privatebin/privatebinEPSS 0.22%via NVD