Vulnerabilities (CVE)

Filtered by vendor Torrentpier
Filtered by product Torrentpier
Angry Yack Logo
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-64519 1 Torrentpier 1 Torrentpier 2025-12-31 N/A 8.8 HIGH
TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including 2.8.8, an authenticated SQL injection vulnerability exists in the moderator control panel (`modcp.php`). Users with moderator permissions can exploit this vulnerability by supplying a malicious `topic_id` (`t`) parameter. This allows an authenticated moderator to execute arbitrary SQL queries, leading to the potential disclosure, modification, or deletion of any data in the dat ...

Show More

CVE-2024-1651 1 Torrentpier 1 Torrentpier 2025-02-12 N/A 10.0 CRITICAL
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization.