Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Owncast Project

First CVE: Dec 14, 2021Active for: 5 yearsTotal CVEs: 6

Owncast Project maintains a self-hosted live-streaming platform that, despite a narrow product focus, sits at the boundary between user content and network connectivity, creating a meaningful attack surface for server-side and web-layer flaws. Its vulnerability footprint skews strongly toward critical-severity outcomes and frequently acquires public exploit code; the recurring weakness classes—server-side request forgery, cross-site request forgery, code injection, path traversal, and cross-site scripting—reflect the challenges of safely handling untrusted input, user-generated content, and network requests in a streaming application. Defenders deploying Owncast should prioritize patching for these input-handling and injection-class vulnerabilities; current severity, exploitation, and exposure data are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Owncast Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 14, 2021
4 years ago
Most Recent CVE
Apr 19, 2024
826 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-3188MEDIUM
Server-Side Request Forgery (SSRF) in GitHub repository owncast/owncast prior to 0.1.0.
Jun 10, 20236.532NOYES
CVE-2022-3751CRITICAL
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
Nov 29, 20229.830NONO
CVE-2023-46480CRITICAL
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.
Nov 27, 20239.827NONO
CVE-2024-29026CRITICAL
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make
Mar 20, 20249.126NONO
CVE-2021-39183MEDIUM
Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are executed when Javascript is parsed via a paste action. This iss
Dec 14, 20216.121NONO
CVE-2024-31450MEDIUM
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast application exposes an administrator API at the URL /api/admin.
Apr 19, 20246.520NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low0 (0.0%)
High1 (16.7%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Owncast Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Owncast Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Owncast Project's Products

View all 3 CNAs →

Top CWEs