torrentpier/torrentpier
TorrentPier. Bull-powered BitTorrent tracker engine
Activity
- Latest release
- 4mo ago
- Total releases
- 65
- Cadence
- ~5 days
- Last 12 months
- 10
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Jun 12, 2017
| Version | Released | |
|---|---|---|
v3.0.5
patch
deprecated
|
v3.0.5
patch
deprecated
Dependencies (49)
+ 41 more
Changelog
Compare changes
|
|
v3.0.4
patch
| ||
v3.0.3
patch
| ||
v3.0.2
patch
| ||
v3.0.1
patch
| ||
v3.0.0
major
| ||
v2.8.9
patch
|
v2.8.9
patch
Dependencies (34)
+ 26 more
Changelog
Compare changes
|
|
v2.8.8
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.8.8
patch
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
v2.8.7
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.8.7
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
v2.8.6
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.8.5
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.8.5
patch
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
v2.8.4.1
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.8.4
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.13
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.13
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v2.4.12
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.12
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v2.4.11
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.10
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.10
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v2.8.3
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.8.3
patch
Dependencies (26)
+ 18 more
Changelog
Compare changes
|
|
v2.4.9
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.8.2
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.8
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.7
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.8.1
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.8.0
minor
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.7.0
minor
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.6
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.6.0
minor
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.6.0
minor
Dependencies (30)
+ 22 more
Changelog
Compare changes
|
|
v2.5.0
minor
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.5.0
minor
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v2.4.6-alpha.4
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.6-alpha.3
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.6-alpha.2
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.6-alpha.1
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.5
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.5-rc.5
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.5-rc.5
pre
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v2.4.5-rc.4
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.5-rc.4
pre
Dependencies (29)
+ 21 more
Changelog
Compare changes
|
|
v2.4.5-rc.3
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.5-rc.3
pre
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v2.4.5-rc.2
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev | ||
v2.4.5-rc.1
pre
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.5-rc.1
pre
Dependencies (25)
+ 17 more
Changelog
Compare changes
|
|
v2.4.4
patch
1 CVE
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev |
v2.4.4
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v2.4.3
patch
3 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev |
v2.4.3
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
v2.4.2
patch
3 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev |
v2.4.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
v2.4.1
patch
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev | ||
v2.4.0
minor
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev |
v2.4.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v2.4.0-rc2
pre
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev |
v2.4.0-rc2
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
v2.4.0-rc1
pre
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev |
v2.4.0-rc1
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
v2.4.0-beta4
pre
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev |
v2.4.0-beta4
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v2.4.0-beta3
pre
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev | ||
v2.4.0-beta2
pre
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev |
v2.4.0-beta2
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v2.4.0-beta1
pre
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev |
v2.4.0-beta1
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
v2.4.0-alpha4
pre
4 CVEs
GHSA-h29g-c9cx-c73q
May 11, 2026
torrentpier has PHP Serialize Injections
Critical
SummaryHi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system. DetailsIn the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it. PoCAbout UsWe are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach. If you have any questions, email us at support@phpsecure.net" Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References Updated May 11, 2026 · Source: OSV.dev
CVE-2025-64519
GHSA-4rwr-8c3m-55f6
Nov 10, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
SummaryAn authenticated SQL injection vulnerability exists in the moderator control panel ( DetailsThe vulnerability is triggered when This occurs within the initial data retrieval block for a given topic ID. Vulnerable Code Block in
In the PoCThis is a time-based blind SQL injection vulnerability that requires moderator privileges. Prerequisites:
Steps to Reproduce:
ImpactThis is an authenticated SQL Injection vulnerability. Although it requires moderator privileges, it is still severe. A malicious or compromised moderator account can leverage this vulnerability to:
Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 46 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.5-rc.1
v2.4.5-rc.2
v2.4.5-rc.3
v2.4.5-rc.4
v2.4.5-rc.5
v2.4.6
v2.4.6-alpha.1
v2.4.6-alpha.2
v2.4.6-alpha.3
v2.4.6-alpha.4
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.4.1
v2.8.5
v2.8.6
v2.8.7
v2.8.8
Fixed in
2.8.9
References Updated May 13, 2026 · Source: OSV.dev
CVE-2024-40624
GHSA-fg86-4c2r-7wxw
Jul 15, 2024
TorrentPier Deserialization of Untrusted Data vulnerability
Critical
Network
Low
None
None
SummaryIn https://github.com/torrentpier/torrentpier/blob/84f6c9f4a081d9ffff4c233098758280304bf50f/library/includes/functions.php#L41-L60 PoCOne can use Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 14 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
v2.4.2
v2.4.3
Fixed in
2.4.4
References
Updated May 13, 2026 · Source: OSV.dev
CVE-2024-1651
GHSA-5rwm-2xw8-hh9p
Feb 20, 2024
Deserialization of Untrusted Data in Torrentpier
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
Torrentpier version 2.4.1 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to insecure deserialization. Affected versions
2.3.0.4-beta
2.3.0.4-beta2
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1
v2.3.1-rc1
+ 12 more Show less
v2.4.0
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.1
References Updated Feb 12, 2025 · Source: OSV.dev |