Ultimaker manufactures a focused line of 3D printers and associated firmware, with vulnerability exposure concentrated in the control interfaces and web-based management layers of its hardware product family. The durable signal centers on application-layer weaknesses including cross-site request forgery, code injection, and improper UI-layer controls that characterize web-facing embedded device management. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultimaker over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34086HIGH In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver hosts APIs vulnerable to CSRF. Th | Jan 10, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-8374HIGH UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from impr | Sep 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2021-34087HIGH In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. Thi | Jan 10, 2022 | 7.1 | 23 | NO | NO |
CVE-2024-51330MEDIUM An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application an | Nov 15, 2024 | 5.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultimaker.
Media articles that mention a CVE ID that affects a product developed by Ultimaker — matched by CVE ID, not by vendor name.