Launch Week Day 1: Announcing Security Design Review
38 Total advisories
38 Vulnerabilities
0 Malware

Vulnerabilities

CRITICAL 9.4
PyPI

CVE-2024-32977

CVE-2024-32977

MEDIUM 4.0
PyPI

CVE-2024-28237

XSS via the "Snapshot Test" feature in Classic Webcam plugin settings

HIGH 7.1
PyPI

CVE-2024-32977

OctoPrint has an Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled

MEDIUM 4.8
PyPI

CVE-2024-28237

CVE-2024-28237

UNKNOWN
PyPI

CVE-2021-32561

CVE-2021-32561

UNKNOWN
PyPI

CVE-2021-32560

CVE-2021-32560

HIGH 7.8
PyPI

CVE-2022-2930

CVE-2022-2930

UNKNOWN
PyPI

CVE-2022-3068

CVE-2022-3068

UNKNOWN
PyPI

CVE-2022-2888

CVE-2022-2888

UNKNOWN
PyPI

CVE-2022-2872

CVE-2022-2872

UNKNOWN
PyPI

CVE-2022-3607

CVE-2022-3607

MEDIUM 5.9
PyPI

CVE-2026-23892

OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

UNKNOWN
PyPI

CVE-2025-64187

OctoPrint vulnerable to XSS in Action Commands Notification and Prompt

HIGH 8.8
PyPI

CVE-2025-58180

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

MEDIUM 4.3
PyPI

CVE-2025-32788

OctoPrint Authenticated Reverse Proxy Page Authentication Bypass

MEDIUM 4.3
PyPI

CVE-2025-32788

CVE-2025-32788

MEDIUM 6.5
PyPI

CVE-2025-48879

OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint

MEDIUM 5.4
PyPI

CVE-2025-48067

OctoPrint vulnerable to possible file extraction via upload endpoints

MEDIUM 5.3
PyPI

CVE-2024-51493

OctoPrint has API key access in settings without reauthentication

MEDIUM 5.5
PyPI

CVE-2024-49377

OctoPrint Vulnerable to Reflected XSS in Jinja2 Templates

MEDIUM 6.1
PyPI

CVE-2024-49377

CVE-2024-49377

MEDIUM 6.5
PyPI

CVE-2024-51493

CVE-2024-51493

MEDIUM 5.3
PyPI

CVE-2022-2930

Unverified Password Change in OctoPrint

MEDIUM 6.0
PyPI

CVE-2022-3607

OctoPrint vulnerable to Special Element Injection

HIGH 7.5
PyPI

CVE-2022-1430

Cross-site Scripting in OctoPrint

HIGH 8.8
PyPI

CVE-2022-3068

OctoPrint Improper Privilege Management vulnerability

MEDIUM 4.4
PyPI

CVE-2022-2888

OctoPrint vulnerable to Insufficient Session Expiration.

MEDIUM 6.5
PyPI

CVE-2021-32560

OctoPrint Incorrect Access Control

MEDIUM 6.1
PyPI

CVE-2021-32561

OctoPrint API Error Messages vulnerable to XSS

LOW 3.7
PyPI

CVE-2022-2872

OctoPrint vulnerable to Unrestricted Upload of File with Dangerous Type

HIGH 7.5
PyPI

CVE-2022-1432

Cross-site Scripting in OctoPrint

MEDIUM 6.5
PyPI

CVE-2023-41047

OctoPrint vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

LOW 3.7
PyPI

CVE-2022-2822

OctoPrint does not have rate limiting on the login page

MEDIUM 4.2
PyPI

CVE-2024-23637

OctoPrint Unverified Password Change via Access Control Settings

MEDIUM 4.9
PyPI

CVE-2024-23637

CVE-2024-23637

MEDIUM 6.5
PyPI

CVE-2023-41047

CVE-2023-41047

UNKNOWN
PyPI

CVE-2022-1432

CVE-2022-1432

UNKNOWN
PyPI

CVE-2022-1430

CVE-2022-1430

Ready to move

Start Securing

Free, no credit card | First findings in minutes