VYPR

Pingvin Share X

by Pingvin Share X

Source repositories

CVEs (3)

  • CVE-2025-22137CriJan 8, 2025
    risk 0.57cvss 9.8epss 0.01

    Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an authenticated or unauthenticated (if anonymous shares are allowed) user to overwrite arbitrary files on the server, including sensitive system files, via HTTP…

  • CVE-2026-44196CriMay 12, 2026
    risk 0.52cvss 9.1epss 0.00

    Pingvin Share X is a secure and easy self-hosted file sharing platform. From 1.14.1 to 1.16.2, a critical authentication bypass vulnerability allows an attacker who has obtained a valid username and password to skip the second-factor authentication (TOTP) requirement entirely.…

  • CVE-2026-49467HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on…