Framasoft develops a focused line of open-source collaboration and media-sharing applications, with its vulnerability footprint concentrated in PeerTube and Framadate, both of which see deployment in federated and privacy-conscious environments. The recurring weakness classes—improper access control, inadequate ownership management, server-side request forgery, type confusion, and data-amplification handling—reflect the complexity of distributed architectures and multi-user request processing that characterize these platforms. Current severity, exploitation, and remediation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Framasoft over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1000039CRITICAL Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution | Jul 17, 2017 | 9.8 | 28 | NO | NO |
CVE-2022-0132HIGH peertube is vulnerable to Server-Side Request Forgery (SSRF) | Jan 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-0881MEDIUM Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. | Mar 9, 2022 | 6.5 | 23 | NO | NO |
CVE-2025-32948HIGH The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send Activit | Apr 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-32947HIGH This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPu | Apr 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2021-3780MEDIUM peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sep 15, 2021 | 6.1 | 21 | NO | NO |
CVE-2025-32944MEDIUM The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner. If user import is enabled (which is the default setting), | Apr 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-32949MEDIUM This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb.
If user import is enabled (which is t | Apr 15, 2025 | 6.5 | 19 | NO | NO |
CVE-2022-0133HIGH peertube is vulnerable to Improper Access Control | Jan 10, 2022 | 7.5 | 19 | NO | NO |
CVE-2022-0170MEDIUM peertube is vulnerable to Improper Access Control | Jan 11, 2022 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Framasoft.
Media articles that mention a CVE ID that affects a product developed by Framasoft — matched by CVE ID, not by vendor name.