Electrum is a lightweight Bitcoin wallet whose vulnerability footprint centers on command-handling and authorization issues in the wallet application itself, including argument injection, OS command injection, and missing authorization controls. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Electrum over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6353HIGH The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code tha | Jan 27, 2018 | 7.8 | 25 | NO | NO |
CVE-2022-31246MEDIUM paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR code data). On Windows, this can lead to capture of credent | Jun 17, 2022 | 5.5 | 19 | NO | NO |
CVE-2018-1000022MEDIUM Electrum Technologies GmbH Electrum Bitcoin Wallet version prior to version 3.0.5 contains a Missing Authorization vulnerability in JSONRPC interface that can result in Bitcoin the | Feb 9, 2018 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Electrum.
Media articles that mention a CVE ID that affects a product developed by Electrum — matched by CVE ID, not by vendor name.