VYPR

Octoprint

by Octoprint

pypi: octoprint

Source repositories

CVEs (27)

  • CVE-2018-16710CriSep 7, 2018
    risk 0.59cvss 9.1epss 0.02

    OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting…

  • CVE-2025-58180HigSep 9, 2025
    risk 0.55cvss 8.8epss 0.21

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution…

  • CVE-2022-3068HigSep 21, 2022
    risk 0.50cvss 8.8epss 0.01

    Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.

  • CVE-2022-2930HigAug 22, 2022
    risk 0.44cvss 7.8epss 0.00

    Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.

  • CVE-2022-2822HigAug 15, 2022
    risk 0.42cvss 7.5epss 0.01

    An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.

  • CVE-2022-1430HigMay 18, 2022
    risk 0.42cvss 7.5epss 0.01

    Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.

  • CVE-2021-32560MedMay 11, 2021
    risk 0.42cvss 6.5epss 0.01

    The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.

  • CVE-2021-32561MedMay 11, 2021
    risk 0.40cvss 6.1epss 0.01

    OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.

  • CVE-2026-54134HigAug 21, 2026
    risk 0.39cvss —epss 0.00

    OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_UPLOAD permission to inject reserved…

  • CVE-2024-32977HigMay 14, 2024
    risk 0.39cvss 7.1epss 0.01

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within…

  • CVE-2025-48879MedJun 10, 2025
    risk 0.35cvss 6.5epss 0.00

    OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become unresponsive. The issue can be triggered…

  • CVE-2022-1432MedMay 18, 2022
    risk 0.35cvss 6.4epss 0.01

    Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.

  • CVE-2023-41047MedOct 9, 2023
    risk 0.33cvss 6.2epss 0.01

    OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious admins to configure a specially crafted GCODE script that will allow code execution during rendering of that script. An attacker might use…

  • CVE-2022-3607MedOct 19, 2022
    risk 0.32cvss 6.0epss 0.00

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.

  • CVE-2026-94490MedSep 22, 2026
    risk 0.31cvss 4.7epss 0.02

    A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command API. Performing a manipulation of the argument command results in os command injection. It…

  • CVE-2026-23892MedJan 27, 2026
    risk 0.31cvss 5.9epss 0.00

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network. Due to using character based comparison that…

  • CVE-2024-49377MedNov 5, 2024
    risk 0.29cvss 5.5epss 0.00

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog and the standalone application key confirmation dialog. An attacker who successfully talked a…

  • CVE-2026-94489MedSep 22, 2026
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. Such manipulation of the argument filename leads to path traversal. The attack may be…

  • CVE-2025-48067MedJun 10, 2025
    risk 0.28cvss 5.4epss 0.00

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by…

  • CVE-2022-2872MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.

Page 1 of 2