CVE Tools

Telegram

14 CVEs tracked since 2018. Since Sep 2018, none of them reached CISA KEV.

Telegram CVEs per month

Sep 2018 to May 2021. Point at a month, or focus the strip and use the arrow keys.
Telegram CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0930
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-0230
2021-03null or fewer
2021-04null or fewer
2021-0580

Products

The products that kept showing up in Telegram's monthly top three, with their CVEs summed over those months.

  1. Telegram112 months
  2. Telegram Desktop31 month
  3. Telegram Messenger11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Telegram.

  1. CVE-2026-94488Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unle...8.2
  2. CVE-2026-7701Telegram Desktop Bot API url_auth_box.cpp RequestButton null pointer dereference4.3
  3. CVE-2021-47793Telegram Desktop 2.9.2 - Denial of Service (PoC)7.5
  4. CVE-2024-7014Improper multimedia file attachment validation in Telegram for Android app8.1
  5. CVE-2023-34658Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.5.3
  6. CVE-2023-26818Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.5.5
  7. CVE-2022-43363Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relationship between the Pastebin informatio...6.1
  8. CVE-2021-41861The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of t...3.3
  9. CVE-2021-40532Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.9.8
  10. CVE-2021-37596Telegram Web K Alpha 0.6.1 allows XSS via a document name.6.1
  11. CVE-2021-36769A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different...5.3
  12. CVE-2021-31315Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of the rlottie library. A remote attacker...5.5
  13. CVE-2021-31317Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker...5.5
  14. CVE-2021-31318Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function of their custom fork of the rlottie li...5.5
  15. CVE-2021-31319Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A r...5.5

The record

Peak rank
#68 in May 2021
Busiest month shown
May 2021, 8 CVEs
Months with a KEV entry
0 since Sep 2018
Monthly snapshots
3 since 2018
Telegram's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store