Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Octoprint

First CVE: Sep 7, 2018Active for: 8 yearsTotal CVEs: 23
38.3
VTI Score
Medium

OctoPrint is a widely deployed web-based control and monitoring platform for 3D printers that attracts vulnerability disclosures despite a narrow product footprint, reflecting both its popularity in maker and industrial communities and its direct exposure to network-connected devices. The vulnerability profile centers on authentication and input-handling weaknesses, including cross-site scripting, unverified password changes, authentication bypass via spoofing, and exposure of sensitive information, which are characteristic of web applications that manage device access and user state. A moderate share of the vendor's disclosures reach serious severity levels, and while public exploit code availability remains limited, the nature of these flaws—particularly those affecting authentication and session management—creates material risk in environments where the printer controls are accessible from untrusted networks. Defenders should prioritize inventory of deployed instances, restrict network access to the web interface, and apply updates promptly when authentication or XSS flaws are disclosed. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Octoprint over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 2018
7 years ago
Most Recent CVE
Jan 27, 2026
180 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-58180HIGH
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attac
Sep 9, 20258.850NOYES
CVE-2022-3068HIGH
Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.
Sep 21, 20228.828NONO
CVE-2018-16710CRITICAL
OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significa
Sep 7, 20189.128NONO
CVE-2022-2930HIGH
Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
Aug 22, 20227.826NONO
CVE-2022-2822HIGH
An attacker can freely brute force username and password and can takeover any account. An attacker could easily guess user passwords and gain access to user and administrative acco
Aug 15, 20227.525NONO
CVE-2024-32977CRITICAL
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerability that allows an unauthenticated att
May 14, 20249.424NONO
CVE-2026-23892MEDIUM
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability t
Jan 27, 20265.922NONO
CVE-2022-3607MEDIUM
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.
Oct 19, 20226.022NONO
CVE-2021-32560MEDIUM
The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.
May 11, 20216.521NONO
CVE-2023-41047MEDIUM
OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious admins to configure a specially crafted
Oct 9, 20236.520NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
70%
22%
9%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (21.7%)
Network15 (65.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (13.0%)
Attack Complexity
Low20 (87.0%)
High3 (13.0%)
Unknown0 (0.0%)
User Interaction
None15 (65.2%)
Unknown0 (0.0%)
Required8 (34.8%)
Privileges Required
Low8 (34.8%)
High5 (21.7%)
None10 (43.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Octoprint.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Octoprint — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Octoprint's Products

View all 3 CNAs →

Top CWEs