Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

opencast — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in opencast, with AI-generated Chinese analysis, references, and POCs.

This page covers vulnerability aggregations for the OpenCast product within the category of information security weaknesses. It collects a comprehensive list of known security flaws, ranging from critical remote code execution risks to minor configuration issues, covering vulnerabilities disclosed from 2018 through the present day. Readers can use this resource to track vendor advisories and monitor security updates issued by the OpenCast team or associated contributors. The data allows users to understand the broader context of specific weakness classes affecting the application, such as improper input validation or privilege escalation flaws. Furthermore, individuals can look up the product's vulnerability history to assess its security posture over time, identifying trends in release stability and patch management responsiveness. This aggregation serves as a factual record of reported issues without offering commentary or recommendations on mitigation strategies. The information is organized to facilitate easy review by system administrators, security analysts, and developers who rely on OpenCast for media management and streaming services. By consolidating these reports, the page provides a clear view of the attack surface associated with the software across different versions. Users are encouraged to consult official vendor documentation and security bulletins for the most current remediation guidance. This collection does not imply endorsement or condemnation of the product but rather presents an objective snapshot of historical security incidents. It is designed to support informed decision-making regarding system upgrades and network segmentation policies for environments utilizing OpenCast infrastructure.

Vendor: opencast

CVE IDTitleCVSSSeverityPublished
CVE-2025-61906 Opencast's editor accidentally publishes videos/overwrites publications #1626 CWE-200 3.5AILowAI2025-10-08
CVE-2025-61788 Opencast Paella Player 7 vulnerable to Cross-Site-Scripting CWE-79 5.4AIMediumAI2025-10-08
CVE-2025-55202 Opencast has a partial path traversal vulnerability in UI config CWE-23 6.5 -2025-08-29
CVE-2025-54380 Opencast still publishes global system account credentials CWE-200 6.5 Medium2025-07-26
CVE-2024-52797 Searching Opencast may cause a denial of service CWE-770 6.5 Medium2024-11-21
CVE-2022-41965 Opencast Authenticated OpenRedirect Vulnerability CWE-601 5.7 Medium2022-11-28
CVE-2022-29237 Limited Authentication Bypass for Media Files in Opencast CWE-287 5.4 Medium2022-05-24
CVE-2021-43821 Files Accessible to External Parties in Opencast CWE-552 9.9 Critical2021-12-14
CVE-2021-43807 HTTP Method Spoofing in Opencast CWE-290 7.5 High2021-12-14
CVE-2021-32623 Opencast vulnerable to billion laughs attack (XML bomb) CWE-776 8.1 High2021-06-15
CVE-2021-21318 Removing access may not effect published series CWE-863 5.4 Medium2021-02-18
CVE-2020-26234 Disabled Hostname Verification in OpenCast CWE-346 4.8 Medium2020-12-08
CVE-2020-5206 Authentication Bypass For Endpoints With Anonymous Access in OpenCast CWE-285 8.7 High2020-01-30
CVE-2020-5231 Opencast users with ROLE_COURSE_ADMIN can create new users CWE-285 4.8 Medium2020-01-30
CVE-2020-5230 Opencast uses unsafe identifiers CWE-99 7.7 High2020-01-30
CVE-2020-5222 Hard-Coded Key Used For Remember-me Token in OpenCast CWE-798 6.8 Medium2020-01-30
CVE-2020-5229 Opencast stores passwords using outdated MD5 hash algorithm CWE-327 7.7 High2020-01-30
CVE-2020-5228 Opencast allows unauthorized public access via OAI-PMH CWE-862 7.6 High2020-01-30

All 18 known CVE vulnerabilities affecting opencast with full Chinese analysis, references, and POCs where available.