Planetestream offers a video streaming and content management platform whose vulnerability profile centers on its Planet eStream product and skews toward serious outcomes with a meaningful share reaching critical severity. The recurring exposure reflects application-layer input-handling and access-control weaknesses including cross-site scripting, SQL injection, path traversal, excessive authentication attempts, and resource exposure, typical of web-facing platforms where request parsing and privilege boundaries are persistent attack surfaces. Current exploitation activity, severity breakdowns, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Planetestream over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45896CRITICAL Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/Process | Dec 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-45891CRITICAL Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.a | Dec 25, 2022 | 9.1 | 29 | NO | NO |
CVE-2022-45889HIGH Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute a | Dec 25, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-45894MEDIUM GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files. | Dec 25, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-45893HIGH Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-for | Dec 25, 2022 | 8.8 | 22 | NO | NO |
CVE-2022-45890MEDIUM In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo pa | Dec 25, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-45892MEDIUM In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, | Dec 25, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-45895MEDIUM Planet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx in some situations) and the WhoAmI endpoin | Dec 25, 2022 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Planetestream.
Media articles that mention a CVE ID that affects a product developed by Planetestream — matched by CVE ID, not by vendor name.