Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Qt — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting Qt. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page provides a comprehensive aggregation of identified weaknesses within the Qt software vendor’s ecosystem. It specifically targets Common Weakness Enumeration (CWE) classifications that have been reported or confirmed in Qt-based products, offering a centralized view of security issues affecting this widely used cross-platform application development framework. The content collected spans historical reports dating back several years through current findings, ensuring a long-term perspective on the vendor’s security posture and the evolution of vulnerabilities within its codebase over time. By utilizing this resource, security analysts and developers can effectively track official advisories issued by the Qt Company as well as independent disclosures from the research community. Users can gain a deeper understanding of prevalent weakness classes that impact Qt libraries, such as memory corruption or input validation errors, and examine the specific products or components most frequently affected. Additionally, the page allows for detailed lookup of a specific product’s vulnerability history, enabling stakeholders to assess risk exposure across different versions and releases. This structured approach facilitates better decision-making for patching strategies, dependency management, and overall application security hardening initiatives related to Qt technologies. The information is presented objectively to support technical evaluation without bias or promotional language, focusing strictly on factual data and recognized vulnerability metrics.

Top products by Qt: Qt Axivion
CVE IDTitleCVSSSeverityPublished
CVE-2026-15037 XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization — QtCWE-91 2.9 Low2026-07-23
CVE-2026-9499 Out-of-bounds read in QTextCodec::codecForName() in Qt — QtCWE-125--2026-07-21
CVE-2026-12379 URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of Axivion — AxivionCWE-601--2026-07-16
CVE-2026-12593 Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem — AxivionCWE-862--2026-07-09
CVE-2025-14575 Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading — QtCWE-427 1.8 Low2026-05-19
CVE-2026-6210 Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash — QtCWE-843 8.7 High2026-05-06
CVE-2025-14576 Possible QML code injection in VectorImage component — QtCWE-94 7.4 High2026-04-30
CVE-2025-12385 Improper validation of <img> tag size in Text component parser — QtCWE-770 8.7 High2025-12-03
CVE-2025-23050 Qt 缓冲区错误漏洞 — QtCWE-125 3.1 Low2025-10-31
CVE-2025-6338 Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend — QtCWE-459 9.2 Critical2025-10-16
CVE-2025-10729 Use-after-free vulnerability in Qt SVG qsvghandler.cpp allows denial of service via crafted SVG — QtCWE-416 9.4 Critical2025-10-03
CVE-2025-10728 Uncontrolled recursion in Qt SVG module — QtCWE-674 9.4 Critical2025-10-03
CVE-2025-5992 Passing values outside of expected range to QColorTransferGenericFunction can cause a denial of service — QtCWE-20 2.3 Low2025-07-11
CVE-2025-5991 Use after free in QHttp2ProtocolHandler — QtCWE-416 2.1 Low2025-06-11
CVE-2025-5683 Qt 安全漏洞 — Qt 5.1 Medium2025-06-05
CVE-2025-5455 Possible denial of service when passing malformed data in a URL to qDecodeDataUrl — QtCWE-20 8.4 High2025-06-02
CVE-2025-4211 Improper Link Resolution Before File Access in QFileSystemEngine on Windows — QtCWE-59 7.3 High2025-05-16
CVE-2025-3512 Buffer overflow in QTextMarkdownImporter — QtCWE-122 4.8 Medium2025-04-11
CVE-2025-30348 Qt 安全漏洞 — QtCWE-407 5.8 Medium2025-03-21

This page lists every published CVE security advisory associated with Qt. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.