VendorsPopcorn Time Projectpopcorn_timeall versions
Vulnerabilities

Popcorn Time Project Popcorn Time

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2022-25229
Popcorn Time 0.4.7 has a Stored XSS in the 'Movies API Server(s)' field via the 'settings' page. The 'nodeIntegration' configuration is set to on which allows the 'webpage' to use 'NodeJs' features, an attacker can leverage this to run OS commands.
Published 2022-05-20 · Modified
5.4EPSS 0.006