38 Total advisories
38 Vulnerabilities
0 Malware
Vulnerabilities
CRITICAL 9.4
CVE-2024-32977
CVE-2024-32977
MEDIUM 4.0
CVE-2024-28237
XSS via the "Snapshot Test" feature in Classic Webcam plugin settings
HIGH 7.1
CVE-2024-32977
OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled
MEDIUM 4.8
CVE-2024-28237
CVE-2024-28237
UNKNOWN
CVE-2021-32561
CVE-2021-32561
UNKNOWN
CVE-2021-32560
CVE-2021-32560
HIGH 7.8
CVE-2022-2930
CVE-2022-2930
UNKNOWN
CVE-2022-3068
CVE-2022-3068
UNKNOWN
CVE-2022-2888
CVE-2022-2888
UNKNOWN
CVE-2022-2872
CVE-2022-2872
UNKNOWN
CVE-2022-3607
CVE-2022-3607
MEDIUM 5.9
CVE-2026-23892
OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
UNKNOWN
CVE-2025-64187
OctoPrint vulnerable to XSS in Action Commands Notification and Prompt
HIGH 8.8
CVE-2025-58180
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
MEDIUM 4.3
CVE-2025-32788
OctoPrint Authenticated Reverse Proxy Page Authentication Bypass
MEDIUM 4.3
CVE-2025-32788
CVE-2025-32788
MEDIUM 6.5
CVE-2025-48879
OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
MEDIUM 5.4
CVE-2025-48067
OctoPrint vulnerable to possible file extraction via upload endpoints
MEDIUM 5.3
CVE-2024-51493
OctoPrint has API key access in settings without reauthentication
MEDIUM 5.5
CVE-2024-49377
OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates
MEDIUM 6.1
CVE-2024-49377
CVE-2024-49377
MEDIUM 6.5
CVE-2024-51493
CVE-2024-51493
MEDIUM 5.3
CVE-2022-2930
Unverified Password Change in OctoPrint
MEDIUM 6.0
CVE-2022-3607
OctoPrint vulnerable to Special Element Injection
HIGH 7.5
CVE-2022-1430
Cross-site Scripting in OctoPrint
HIGH 8.8
CVE-2022-3068
OctoPrint Improper Privilege Management vulnerability
MEDIUM 4.4
CVE-2022-2888
OctoPrint vulnerable to Insufficient Session Expiration.
MEDIUM 6.5
CVE-2021-32560
OctoPrint Incorrect Access Control
MEDIUM 6.1
CVE-2021-32561
OctoPrint API Error Messages vulnerable to XSS
LOW 3.7
CVE-2022-2872
OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type
HIGH 7.5
CVE-2022-1432
Cross-site Scripting in OctoPrint
MEDIUM 6.5
CVE-2023-41047
OctoPrint vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
LOW 3.7
CVE-2022-2822
OctoPrint does not have rate limiting on the login page
MEDIUM 4.2
CVE-2024-23637
OctoPrint Unverified Password Change via Access Control Settings
MEDIUM 4.9
CVE-2024-23637
CVE-2024-23637
MEDIUM 6.5
CVE-2023-41047
CVE-2023-41047
UNKNOWN
CVE-2022-1432
CVE-2022-1432
UNKNOWN
CVE-2022-1430
CVE-2022-1430
Ready to move
Start Securing
Free, no credit card | First findings in minutes