Torrentpier is a niche torrent-tracking and community platform whose vulnerability profile centers on its core application and recurs through deserialization of untrusted data and SQL injection weaknesses, both characteristic of server-side applications handling user input and session state. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Torrentpier over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1651CRITICAL Torrentpier version 2.4.1 allows executing arbitrary commands on the server.
This is possible because the application is vulnerable to insecure deserialization.
| Feb 20, 2024 | 9.8 | 49 | NO | NO |
CVE-2025-64519HIGH TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL injection vulnerability exists i | Nov 10, 2025 | 8.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Torrentpier.
Media articles that mention a CVE ID that affects a product developed by Torrentpier — matched by CVE ID, not by vendor name.