← Back

Deluge

deluge

Vendor: Deluge Torrent • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Deluge Torrent
1Deluge
Jun 17, 2026
Mar 22, 2026
6.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into...Show more
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' field during torrent addition to trigger an application crash.Show less
1Deluge Torrent
1Deluge
Jun 17, 2026
Mar 22, 2026
6.9 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into...Show more
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into the Webseeds field during torrent creation to trigger an application crash.Show less
1Deluge Torrent
1Deluge
Jun 17, 2026
Aug 26, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torren...Show more
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.Show less
1Deluge Torrent
1Deluge
May 13, 2026
May 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The WebUI component in Deluge before 1.3.15 contains a directory traversal vulnerability involving a request in which the name of the render file is not associated with any template file.
2Debian
Deluge Torrent
2Debian Linux
Deluge
May 13, 2026
Mar 18, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to dow...Show more
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.Show less