Popcorn Time Project maintains a media streaming application that has attracted modest vulnerability disclosures, primarily centered on the flagship Popcorn Time product itself. The observed weakness class reflects web-interface input-handling risks, specifically cross-site scripting conditions that arise in the application's page-generation logic. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Popcorn Time Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25229MEDIUM Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use | May 20, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Popcorn Time Project.
Media articles that mention a CVE ID that affects a product developed by Popcorn Time Project — matched by CVE ID, not by vendor name.