Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

opencast — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in opencast, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page compiles security advisories for the OpenCast media production platform, focusing on identified software weaknesses. It collects public records of flaws such as memory errors, authentication bypasses, and configuration issues reported within the last five years. Here, you can track the vendor's security releases, analyze the prevalence of specific weakness classes, and review the complete vulnerability history associated with OpenCast versions.

Vendor: opencast

CVE ID Title CVSS Severity Published
CVE-2026-77615 Paella Player: Stored XSS via caption cue text CWE-79 8.7 High 2026-09-17
CVE-2026-77614 Opencast: Session fixation in login enables account takeover via crafted link CWE-384 8.8 High 2026-09-17
CVE-2025-61906 Opencast's editor accidentally publishes videos/overwrites publications #1626 CWE-200 3.5AI Low AI 2025-10-08
CVE-2025-61788 Opencast Paella Player 7 vulnerable to Cross-Site-Scripting CWE-79 5.4AI Medium AI 2025-10-08
CVE-2025-55202 Opencast has a partial path traversal vulnerability in UI config CWE-23 6.5 - 2025-08-29
CVE-2025-54380 Opencast still publishes global system account credentials CWE-200 6.5 Medium 2025-07-26
CVE-2024-52797 Searching Opencast may cause a denial of service CWE-770 6.5 Medium 2024-11-21
CVE-2022-41965 Opencast Authenticated OpenRedirect Vulnerability CWE-601 5.7 Medium 2022-11-28
CVE-2022-29237 Limited Authentication Bypass for Media Files in Opencast CWE-287 5.4 Medium 2022-05-24
CVE-2021-43821 Files Accessible to External Parties in Opencast CWE-552 9.9 Critical 2021-12-14
CVE-2021-43807 HTTP Method Spoofing in Opencast CWE-290 7.5 High 2021-12-14
CVE-2021-32623 Opencast vulnerable to billion laughs attack (XML bomb) CWE-776 8.1 High 2021-06-15
CVE-2021-21318 Removing access may not effect published series CWE-863 5.4 Medium 2021-02-18
CVE-2020-26234 Disabled Hostname Verification in OpenCast CWE-346 4.8 Medium 2020-12-08
CVE-2020-5206 Authentication Bypass For Endpoints With Anonymous Access in OpenCast CWE-285 8.7 High 2020-01-30
CVE-2020-5231 Opencast users with ROLE_COURSE_ADMIN can create new users CWE-285 4.8 Medium 2020-01-30
CVE-2020-5230 Opencast uses unsafe identifiers CWE-99 7.7 High 2020-01-30
CVE-2020-5222 Hard-Coded Key Used For Remember-me Token in OpenCast CWE-798 6.8 Medium 2020-01-30
CVE-2020-5229 Opencast stores passwords using outdated MD5 hash algorithm CWE-327 7.7 High 2020-01-30
CVE-2020-5228 Opencast allows unauthorized public access via OAI-PMH CWE-862 7.6 High 2020-01-30

All 20 known CVE vulnerabilities affecting opencast with full Chinese analysis, references, and POCs where available.