pocketbase CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

pocketbase vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to pocketbase, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-44166 Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker knows the email address of the victim they can create and link an unverified PocketBase user in advance by authenticating with one of the OAuth2 app providers, e.g. "A". When the victim gets invited or decides to sign up to your app on their own with provider "B" (PocketBase OAuth2 auth requires to be with a different provider because we don't allow multiple OAuth2 accounts fro [email protected] 6.1 0.19% 2026-05-12 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence