Vulnerabilities (CVE)

Filtered by vendor Octoprint Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-1432 1 Octoprint 1 Octoprint 2022-05-25 4.6 MEDIUM 6.4 MEDIUM
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2022-1430 1 Octoprint 1 Octoprint 2022-05-25 5.1 MEDIUM 7.5 HIGH
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
CVE-2021-32561 1 Octoprint 1 Octoprint 2021-05-26 4.3 MEDIUM 6.1 MEDIUM
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
CVE-2021-32560 1 Octoprint 1 Octoprint 2021-05-26 4.0 MEDIUM 6.5 MEDIUM
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.
CVE-2018-16710 1 Octoprint 1 Octoprint 2018-11-14 6.4 MEDIUM 9.1 CRITICAL
** DISPUTED ** OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting OctoPrint onto the public internet is a terrible idea, and I really can't emphasize that enough."