Qbittorrent is a widely deployed, single-product open-source BitTorrent client that, despite its narrow portfolio, maintains significant presence across desktop and server environments. Vulnerabilities affecting the application skew strongly toward critical-severity outcomes and frequently acquire public exploit code, with the recurring weakness classes centered on authentication bypass, certificate validation flaws, input validation failures, cross-site scripting, and OS command injection—reflecting the parser and protocol-handling demands of a network application. Defenders should treat this vendor's advisories as urgent given the severity profile and the client's role in automated downloading and system access; live exploitation and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qbittorrent over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-51774HIGH qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors. | Nov 2, 2024 | 8.1 | 37 | NO | YES |
CVE-2019-13640CRITICAL In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name par | Jul 17, 2019 | 9.8 | 33 | NO | NO |
CVE-2023-30801CRITICAL All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administrator is not forced to change the default credentia | Oct 10, 2023 | 9.8 | 24 | NO | NO |
CVE-2017-12778HIGH The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorrent functions by tampering the | May 9, 2019 | 7.1 | 24 | NO | NO |
CVE-2025-54310MEDIUM qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp. | Jul 18, 2025 | 5.3 | 17 | NO | NO |
CVE-2017-6504MEDIUM WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking. | Mar 6, 2017 | 6.1 | 17 | NO | NO |
CVE-2017-6503MEDIUM WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS. | Mar 6, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qbittorrent.
Media articles that mention a CVE ID that affects a product developed by Qbittorrent — matched by CVE ID, not by vendor name.