Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Framasoft

First CVE: Jul 17, 2017Active for: 9 yearsTotal CVEs: 16
17.0
VTI Score
Low

Framasoft develops a focused line of open-source collaboration and media-sharing applications, with its vulnerability footprint concentrated in PeerTube and Framadate, both of which see deployment in federated and privacy-conscious environments. The recurring weakness classes—improper access control, inadequate ownership management, server-side request forgery, type confusion, and data-amplification handling—reflect the complexity of distributed architectures and multi-user request processing that characterize these platforms. Current severity, exploitation, and remediation status are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Framasoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2017
9 years ago
Most Recent CVE
Apr 15, 2025
465 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-1000039CRITICAL
Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution
Jul 17, 20179.828NONO
CVE-2022-0132HIGH
peertube is vulnerable to Server-Side Request Forgery (SSRF)
Jan 10, 20227.525NONO
CVE-2022-0881MEDIUM
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.
Mar 9, 20226.523NONO
CVE-2025-32948HIGH
The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send Activit
Apr 15, 20257.521NONO
CVE-2025-32947HIGH
This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPu
Apr 15, 20257.521NONO
CVE-2021-3780MEDIUM
peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Sep 15, 20216.121NONO
CVE-2025-32944MEDIUM
The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting),
Apr 15, 20256.520NONO
CVE-2025-32949MEDIUM
This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb. If user import is enabled (which is t
Apr 15, 20256.519NONO
CVE-2022-0133HIGH
peertube is vulnerable to Improper Access Control
Jan 10, 20227.519NONO
CVE-2022-0170MEDIUM
peertube is vulnerable to Improper Access Control
Jan 11, 20224.318NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
69%
25%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (93.8%)
Unknown0 (0.0%)
Required1 (6.3%)
Privileges Required
Low8 (50.0%)
High0 (0.0%)
None8 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Framasoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Framasoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Framasoft's Products

View all 3 CNAs →

Top CWEs