Franklioxygen's vulnerability profile centers on a narrowly scoped product line anchored by its MyTube application, yet its disclosures skew strongly toward critical-severity outcomes. The recurring exposure concentrates in access-control and authorization weakness classes—including user-controlled key manipulation, improper access restrictions, and weak authentication enforcement—that are characteristic of application-layer privilege and session management flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Franklioxygen over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-23837CRITICAL MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to | Jan 19, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-33890CRITICAL MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently aut | Mar 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-33735HIGH MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows att | Mar 27, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-33935HIGH MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor accounts from p | Mar 27, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-24139MEDIUM MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, allowing guest users to download | Jan 24, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-24140MEDIUM MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality du | Jan 24, 2026 | 5.3 | 23 | NO | NO |
CVE-2026-23848MEDIUM MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via `X-Forwarded-For` header spoofing allows unauthenticat | Jan 19, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Franklioxygen.
Media articles that mention a CVE ID that affects a product developed by Franklioxygen — matched by CVE ID, not by vendor name.