Vulnerabilities > Owncast Project > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-11-27 CVE-2023-46480 Server-Side Request Forgery (SSRF) vulnerability in Owncast Project Owncast 0.1.1
An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function.
network
low complexity
owncast-project CWE-918
critical
9.8
2022-11-29 CVE-2022-3751 SQL Injection vulnerability in Owncast Project Owncast
SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.
network
low complexity
owncast-project CWE-89
critical
9.8