Vulnerabilities
16 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-32947 | This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receivin This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPub activities. NVD description · AI analysis pending | 7.5 group max | <1% | PoC |
| — | |
| CVE-2022-0881 | Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. NVD description · AI analysis pending | 6.5 | 1% | PoC |
| — | |
| CVE-2022-0727 +1 in the same advisory: …0726 | Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0. Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2022-0508 | Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9d6832 Server-Side Request Forgery (SSRF) in GitHub repository chocobozzz/peertube prior to f33e515991a32885622b217bf2ed1d1b0d9d6832 NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2022-0170 | peertube is vulnerable to Improper Access Control peertube is vulnerable to Improper Access Control NVD description · AI analysis pending | 4.3 | <1% |
| — | ||
| CVE-2022-0133 +1 in the same advisory: …0132 | peertube is vulnerable to Improper Access Control peertube is vulnerable to Improper Access Control NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2021-3780 | peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2017-1000039 | Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution NVD description · AI analysis pending | 9.8 | 3% |
| — |