VYPR
Vendor

Onionshare

Products
1
CVEs
15
Across products
15
Status
Private

Products

1

Recent CVEs

15
  • CVE-2022-21690HigJan 18, 2022
    risk 0.57cvss 8.7epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path parameter of the requested URL is not sanitized before being passed to the QT frontend. This path is…

  • CVE-2022-21689HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions the receive mode limits concurrent uploads to 100 per second and blocks other uploads in the same second, which…

  • CVE-2022-21688HigJan 18, 2022
    risk 0.49cvss 7.5epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Affected versions of the desktop application were found to be vulnerable to denial of service via an undisclosed vulnerability in the…

  • CVE-2018-19960HigDec 7, 2018
    risk 0.39cvss 7.0epss 0.00

    The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users to overwrite files or obtain sensitive information by using this pathname.

  • CVE-2016-5026MedJan 30, 2017
    risk 0.36cvss 5.5epss 0.00

    hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.

  • CVE-2021-41867MedOct 4, 2021
    risk 0.35cvss 5.3epss 0.02

    An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare node via the --chat feature.

  • CVE-2022-21693MedJan 18, 2022
    risk 0.34cvss 6.3epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions an adversary with a primitive that allows for filesystem access from the context of the Onionshare process can…

  • CVE-2026-54707MedJul 31, 2026
    risk 0.28cvss 5.4epss 0.00

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in…

  • CVE-2022-21692MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions anyone with access to the chat environment can write messages disguised as another chat participant.

  • CVE-2022-21695MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated users (or unauthenticated in public mode) can send messages without being visible in the list of…

  • CVE-2022-21691MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions chat participants can spoof their channel leave message, tricking others into assuming they left the chatroom.

  • CVE-2022-21696MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions it is possible to change the username to that of another chat participant with an additional space character at…

  • CVE-2026-54706MedJul 31, 2026
    risk 0.24cvss 4.8epss 0.00

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through…

  • CVE-2022-21694LowJan 18, 2022
    risk 0.24cvss 3.7epss 0.01

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare allows to use a hardened CSP, which will block any scripts and external resources. It is not…

  • CVE-2021-41868CriOct 4, 2021
    risk 0.00cvss 9.8epss 0.02

    OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.