Vulnerabilities > Jellyfin > Jellyfin
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-13 | CVE-2023-48702 | Command Injection vulnerability in Jellyfin Jellyfin is a system for managing and streaming media. | 7.2 |
2023-12-06 | CVE-2023-49096 | Argument Injection or Modification vulnerability in Jellyfin Jellyfin is a Free Software Media System for managing and streaming media. | 8.8 |
2023-04-24 | CVE-2023-30626 | Path Traversal vulnerability in Jellyfin Jellyfin is a free-software media system. | 8.1 |
2023-04-24 | CVE-2023-30627 | Cross-site Scripting vulnerability in Jellyfin jellyfin-web is the web client for Jellyfin, a free-software media system. | 5.4 |
2023-03-10 | CVE-2023-27161 | Server-Side Request Forgery (SSRF) vulnerability in Jellyfin Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. | 7.5 |
2023-02-03 | CVE-2023-23635 | Cross-site Scripting vulnerability in Jellyfin In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. | 5.4 |
2023-02-03 | CVE-2023-23636 | Cross-site Scripting vulnerability in Jellyfin In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. | 5.4 |
2021-05-06 | CVE-2021-29490 | Server-Side Request Forgery (SSRF) vulnerability in Jellyfin Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. | 5.0 |
2021-03-23 | CVE-2021-21402 | Path Traversal vulnerability in Jellyfin Jellyfin is a Free Software Media System. | 4.0 |