CRITICAL9.8CVE-2021-41868Remote unauthenticated attackers able to upload files in Onionshare from 0
from 0, < 2.2-3+deb11u1
HIGH7.0CVE-2018-19960The debug_mode function in web/web.py in OnionShare through 1.3.1, when --debug is enabled, uses the /tmp/onionshare_server.log pathname fo… from 0, < 1.3.2-1
MEDIUM6.5Path traversal in Onionshare
from 0, < 2.5-1
MEDIUM5.5hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
from 0, < 0.8.1-2
MEDIUM5.4OTF-001: Improper Input Sanitation: The path parameter of the requested URL is not sanitized before being passed to the QT frontend
from 0, < 2.2-3+deb11u1
MEDIUM5.3Incorrect Permission Assignment for Critical Resource in OnionShare
from 0
MEDIUM5.3Improper Access Control in Onionshare
from 0, < 2.5-1
MEDIUM5.3Information disclosure vulnerability in OnionShare
from 0, < 2.5-1
MEDIUM4.3Improper Access Control in Onionshare
from 0, < 2.5-1
MEDIUM4.3Improper Access Control in Onionshare
from 0, < 2.5-1
MEDIUM4.3Username spoofing in OnionShare
from 0, < 2.5-1
—(no summary)
from 0
—(no summary)
from 0