Qutebrowser is a lightweight, keyboard-driven web browser with a focused vulnerability footprint centered on input-handling and command-execution surfaces. Its observed weakness classes include cross-site request forgery, argument and command injection, cross-site scripting, and file-resource naming issues, which reflect the interaction between user input, web content, and system-level operations in a browser context. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qutebrowser over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41146HIGH qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL | Oct 21, 2021 | 8.8 | 28 | NO | NO |
CVE-2018-10895HIGH qutebrowser before version 1.4.1 is vulnerable to a cross-site request forgery flaw that allows websites to access 'qute://*' URLs. A malicious website could exploit this to load a | Jul 12, 2018 | 8.8 | 23 | NO | NO |
CVE-2018-1000559MEDIUM qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page tha | Jun 26, 2018 | 6.1 | 20 | NO | NO |
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the | May 7, 2020 | 3.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qutebrowser.
Media articles that mention a CVE ID that affects a product developed by Qutebrowser — matched by CVE ID, not by vendor name.