Octoprint
Products
2- Octoprint25 CVEspypi
- 1 CVE
Recent CVEs
26| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-16710 | Cri | 0.59 | 9.1 | 0.02 | Sep 7, 2018 | OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting… | ||
| CVE-2025-58180 | Hig | 0.55 | 8.8 | 0.21 | Sep 9, 2025 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution… | ||
| CVE-2025-62169 | Hig | 0.53 | 8.1 | 0.00 | Oct 23, 2025 | OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or… | ||
| CVE-2022-3068 | Hig | 0.50 | 8.8 | 0.00 | Sep 21, 2022 | Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3. | ||
| CVE-2026-54134 | hig | 0.45 | — | — | Jun 23, 2026 | ### Impact OctoPrint versions up until and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 contain a vulnerability that allows an attacker with the `FILE_UPLOAD` permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload… | ||
| CVE-2022-2930 | Hig | 0.44 | 7.8 | 0.00 | Aug 22, 2022 | Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3. | ||
| CVE-2022-2822 | Hig | 0.42 | 7.5 | 0.01 | Aug 15, 2022 | An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts. | ||
| CVE-2022-1430 | Hig | 0.42 | 7.5 | 0.01 | May 18, 2022 | Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0. | ||
| CVE-2021-32560 | Med | 0.42 | 6.5 | 0.01 | May 11, 2021 | The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files. | ||
| CVE-2021-32561 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters. | ||
| CVE-2024-32977 | Hig | 0.39 | 7.1 | 0.01 | May 14, 2024 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within… | ||
| CVE-2025-48879 | Med | 0.35 | 6.5 | 0.00 | Jun 10, 2025 | OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become unresponsive. The issue can be triggered… | ||
| CVE-2022-1432 | Med | 0.35 | 6.4 | 0.01 | May 18, 2022 | Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0. | ||
| CVE-2023-41047 | Med | 0.33 | 6.2 | 0.01 | Oct 9, 2023 | OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious admins to configure a specially crafted GCODE script that will allow code execution during rendering of that script. An attacker might use… | ||
| CVE-2022-3607 | Med | 0.32 | 6.0 | 0.00 | Oct 19, 2022 | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3. | ||
| CVE-2026-23892 | Med | 0.31 | 5.9 | 0.00 | Jan 27, 2026 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network. Due to using character based comparison that… | ||
| CVE-2024-49377 | Med | 0.29 | 5.5 | 0.00 | Nov 5, 2024 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog and the standalone application key confirmation dialog. An attacker who successfully talked a… | ||
| CVE-2025-48067 | Med | 0.28 | 5.4 | 0.00 | Jun 10, 2025 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by… | ||
| CVE-2022-2872 | Med | 0.28 | 5.4 | 0.01 | Sep 21, 2022 | Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3. | ||
| CVE-2024-51493 | Med | 0.27 | 5.3 | 0.00 | Nov 5, 2024 | OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary control over an authenticated victim's OctoPrint browser session to… |
- risk 0.59cvss 9.1epss 0.02
OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report because their documentation states that with "blind port forwarding ... Putting…
- risk 0.55cvss 8.8epss 0.21
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution…
- risk 0.53cvss 8.1epss 0.00
OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or…
- risk 0.50cvss 8.8epss 0.00
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
- risk 0.45cvss —epss —
### Impact OctoPrint versions up until and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 contain a vulnerability that allows an attacker with the `FILE_UPLOAD` permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload…
- risk 0.44cvss 7.8epss 0.00
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
- risk 0.42cvss 7.5epss 0.01
An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative accounts.
- risk 0.42cvss 7.5epss 0.01
Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.
- risk 0.42cvss 6.5epss 0.01
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.
- risk 0.40cvss 6.1epss 0.01
OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
- risk 0.39cvss 7.1epss 0.01
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated attacker to completely bypass the authentication if the `autologinLocal` option is enabled within…
- risk 0.35cvss 6.5epss 0.00
OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become unresponsive. The issue can be triggered…
- risk 0.35cvss 6.4epss 0.01
Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.
- risk 0.33cvss 6.2epss 0.01
OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious admins to configure a specially crafted GCODE script that will allow code execution during rendering of that script. An attacker might use…
- risk 0.32cvss 6.0epss 0.00
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.
- risk 0.31cvss 5.9epss 0.00
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network. Due to using character based comparison that…
- risk 0.29cvss 5.5epss 0.00
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected XSS vulnerabilities in the login dialog and the standalone application key confirmation dialog. An attacker who successfully talked a…
- risk 0.28cvss 5.4epss 0.00
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by…
- risk 0.28cvss 5.4epss 0.01
Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.
- risk 0.27cvss 5.3epss 0.00
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerability that allows an attacker that has gained temporary control over an authenticated victim's OctoPrint browser session to…