Skip to main content

CVE-2024-29026

8.2
HIGHCVSS v3.1 Base Score
0.19%
LOW RiskEPSS (41st percentile)

Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. In versions 0.1.2 and prior, a lenient CORS policy allows attackers to make a cross origin request, reading privileged information. This can be used to leak the admin password. Commit 9215d9ba0f29d62201d3feea9e77dcd274581624 fixes this issue.

Published: 3/20/2024
Modified: 10/14/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

EPSS Score (Exploitation Probability)

0.19%LOW Exploitation Risk
41st percentile

This vulnerability has a 0.19% probability of being exploited in the next 30 days, ranking higher than 41% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-352, CWE-697)

CVE-2026-1165MEDIUM 4.3

The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather than one submitted in the request. This makes it possible for unauthenticated attackers to change the publish status of popups via a forged request, granted they can trick a site administrator into performing an action such as clicking a link.

1/31/2026
CVE-2026-22194HIGH 8.8

GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This can be exploited to create privileged accounts by targeting the administrative user creation endpoint.

1/9/2026
CVE-2026-21691MEDIUM 5.4

iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccTag:IsTypeCompressed()`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.

1/7/2026
CVE-2026-21430CRITICAL 9.3

Emlog is an open source website building system. In version 2.5.23, article creation functionality is vulnerable to cross-site request forgery (CSRF). This can lead to a user being forced to post an article with arbitrary, attacker-controlled content. This, when combined with stored cross-site scripting, leads to account takeover. As of time of publication, no known patched versions are available.

1/2/2026
CVE-2025-67013MEDIUM 6.5

The web management interface in ETL Systems Ltd DEXTRA Series ' Digital L-Band Distribution System v1.8 does not implement Cross-Site Request Forgery (CSRF) protection mechanisms (no tokens, no Origin/Referer validation) on critical configuration endpoints.

12/26/2025

Similar SeverityHIGH