Soundcloud operates a focused audio streaming and publishing platform, with its vulnerability history centered on the core service and related shortcode functionality. The durable signal reflects input-handling weaknesses characteristic of web platforms, particularly cross-site scripting and privilege management issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Soundcloud over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-57062MEDIUM An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component. | Mar 13, 2025 | 6.7 | 21 | NO | NO |
CVE-2023-34018MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoundCloud Inc. SoundCloud Shortcode allows Stored XSS.This issue affects Soun | Nov 30, 2023 | 4.8 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Soundcloud.
Media articles that mention a CVE ID that affects a product developed by Soundcloud — matched by CVE ID, not by vendor name.