jellyfin Summary
Latest vulnerabilities published by jellyfin
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
Argument Injection Vulnerability in Jellyfin Media Server
CVE-2025-31499JellyfinJellyfin7.6HIGHIP Spoofing Vulnerability in Jellyfin Media Server
CVE-2025-32012JellyfinJellyfin4.6MEDIUMSpecially crafted SVG file can retrieve AccessToken for Jellyfin administrator
CVE-2024-43801JellyfinJellyfin5.4MEDIUMJellyfin Possible Remote Code Execution via custom FFmpeg binary
CVE-2023-48702jellyfinjellyfin7.2HIGHArgument Injection in FFmpeg codec parameters in Jellyfin
CVE-2023-49096JellyfinJellyfin7.7HIGHJellyfin vulnerable to directory traversal and file write causing arbitrary code execution
CVE-2023-30626JellyfinJellyfin8.8HIGHjellyfin-web has a stored cross-site scripting vulnerability in devices.js
CVE-2023-30627JellyfinJellyfin-web9.1CRITICALServer-Side Request Forgery in Jellyfin Affects Data Access
CVE-2023-27161JellyfinJellyfin7.5HIGHStored XSS Vulnerability in Jellyfin Media Server 10.8.x and Earlier Versions
CVE-2023-23635JellyfinJellyfin5.4MEDIUMStored XSS Vulnerability in Jellyfin Media Server by Jellyfin
CVE-2023-23636JellyfinJellyfin5.4MEDIUMAccess Control Flaw in Jellyfin Media Server by Jellyfin
CVE-2022-35909JellyfinJellyfin8.8HIGHStored XSS Vulnerability in Jellyfin Affecting Admin Access
CVE-2022-35910JellyfinJellyfin5.4MEDIUMUnauthenticated GET requests through Remote Image endpoints
CVE-2021-29490JellyfinJellyfinEPSS 89%5.8MEDIUMUnauthenticated Arbitrary File Access in Jellyfin
CVE-2021-21402JellyfinJellyfinπΎπ‘EPSS 92%7.7HIGH
15 April 2025
2 September 2024
13 December 2023
6 December 2023
24 April 2023
10 March 2023
3 February 2023
19 August 2022
6 May 2021
23 March 2021
No more vulnerabilities to load.