Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Onionshare

First CVE: Jan 30, 2017Active for: 9 yearsTotal CVEs: 13
22.4
VTI Score
Low

Onionshare is a file-sharing tool designed to facilitate anonymous transfer of files over Tor, and its vulnerability profile centers on a single, narrowly scoped product where exposure recurs through authentication and access-control weaknesses, input-validation issues, and path-traversal conditions. A meaningful share of disclosures reach serious severity; defenders relying on this tool for sensitive data transfer should treat authentication bypasses and directory-traversal flaws as priority risks and track updates accordingly. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Onionshare over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 30, 2017
9 years ago
Most Recent CVE
Jan 18, 2022
1,648 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41868CRITICAL
OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --receive functionality.
Oct 4, 20219.832NONO
CVE-2022-21689HIGH
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions the receive m
Jan 18, 20227.525NONO
CVE-2022-21693MEDIUM
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions an adversary
Jan 18, 20226.522NONO
CVE-2018-19960HIGH
The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname for logging, which might allow local users
Dec 7, 20187.021NONO
CVE-2022-21694MEDIUM
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. The website mode of the onionshare
Jan 18, 20225.320NONO
CVE-2022-21690MEDIUM
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions The path para
Jan 18, 20225.420NONO
CVE-2022-21695MEDIUM
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions authenticated
Jan 18, 20225.320NONO
CVE-2022-21688MEDIUM
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Affected versions of the desktop a
Jan 18, 20225.520NONO
CVE-2021-41867MEDIUM
An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve the full list of participants of a non-public OnionShare no
Oct 4, 20215.320NONO
CVE-2016-5026MEDIUM
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
Jan 30, 20175.519NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
77%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (23.1%)
Network10 (76.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (92.3%)
High1 (7.7%)
Unknown0 (0.0%)
User Interaction
None11 (84.6%)
Unknown0 (0.0%)
Required2 (15.4%)
Privileges Required
Low7 (53.8%)
High0 (0.0%)
None6 (46.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Onionshare.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Onionshare — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Onionshare's Products

View all 2 CNAs →

Top CWEs