Peertube
Vendor:
First CVE: Sep 15, 2021 · Active for 4 years
15
Total CVEs
More Total CVEs than 93% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Peertube over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 15, 2021
4 years ago
Most Recent CVE
Apr 15, 2025
468 days ago
CVE Severity & Scoring
Peertube15 CVEs
73%
27%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (93.3%)
Unknown0 (0.0%)
Required1 (6.7%)
Privileges Required
Low8 (53.3%)
High0 (0.0%)
None7 (46.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0132HIGH peertube is vulnerable to Server-Side Request Forgery (SSRF) | Jan 10, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-0881MEDIUM Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. | Mar 9, 2022 | 6.5 | 23 | NO | NO |
CVE-2025-32948HIGH The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send Activit | Apr 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-32947HIGH This vulnerability allows any attacker to cause the PeerTube server to stop responding to requests due to an infinite loop in the "inbox" endpoint when receiving crafted ActivityPu | Apr 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2021-3780MEDIUM peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sep 15, 2021 | 6.1 | 21 | NO | NO |
CVE-2025-32944MEDIUM The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner. If user import is enabled (which is the default setting), | Apr 15, 2025 | 6.5 | 20 | NO | NO |
CVE-2025-32949MEDIUM This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb.
If user import is enabled (which is t | Apr 15, 2025 | 6.5 | 19 | NO | NO |
CVE-2022-0133HIGH peertube is vulnerable to Improper Access Control | Jan 10, 2022 | 7.5 | 19 | NO | NO |
CVE-2022-0170MEDIUM peertube is vulnerable to Improper Access Control | Jan 11, 2022 | 4.3 | 18 | NO | NO |
CVE-2025-32946MEDIUM This vulnerability allows any attacker to add playlists to a different user’s channel using the ActivityPub protocol. The vulnerable code sets the owner of the new playlist to be t | Apr 15, 2025 | 5.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Peertube
Top CWEs
Versions
No cataloged versions.