Product
qbittorrent
7 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-54310
CVE-2024-51774
CVE-2023-30801
CVE-2019-13640
CVE-2017-12778
CVE-2017-6504
CVE-2017-6503
< 5.1.2
qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and
< 5.0.1
qBittorrent before 5.0.1 proceeds with use of https URLs even after certificate validation errors.
<= 4.5.5
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user interface is enabled. The administr
< 4.1.7
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injectio
all versions
The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized
<= 3.3.10
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.
<= 3.3.10
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.