Transmissionbt develops Transmission, a widely deployed open-source BitTorrent client with a modest but prominent CVE footprint reflecting its use across server and desktop environments. The vendor's vulnerability exposure clusters around web-interface and input-handling weaknesses including buffer-boundary violations, cross-site request forgery, path traversal, cross-site scripting, and improper input validation—flaws characteristic of a daemon application that exposes a browser-facing management interface. A meaningful share of these vulnerabilities reach serious severity, and a moderate tendency toward public exploit availability reflects the accessibility of the client to security research. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Transmissionbt over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5702HIGH Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC | Jan 15, 2018 | 8.8 | 44 | NO | YES |
CVE-2010-0748CRITICAL Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. | Oct 30, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-10756HIGH Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafte | May 15, 2020 | 7.8 | 27 | NO | NO |
CVE-2010-0012HIGH Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) i | Jan 8, 2010 | 8.8 | 26 | NO | NO |
CVE-2014-4909MEDIUM Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute | Jul 29, 2014 | 6.8 | 24 | NO | NO |
CVE-2012-6129HIGH Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and | Apr 3, 2013 | 7.5 | 23 | NO | NO |
CVE-2010-1853MEDIUM Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or | May 7, 2010 | 6.8 | 22 | NO | NO |
CVE-2010-0749MEDIUM Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame. | Oct 30, 2019 | 5.3 | 21 | NO | NO |
CVE-2009-1757MEDIUM Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via | May 22, 2009 | 6.8 | 21 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, | Aug 15, 2012 | 2.6 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Transmissionbt.
Media articles that mention a CVE ID that affects a product developed by Transmissionbt — matched by CVE ID, not by vendor name.