VYPR

Jellyfin

by Jellyfin

Source repositories

CVEs (23)

  • CVE-2023-49096HigDec 6, 2023
    risk 0.00cvss 7.7epss 0.01

    Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos//stream` and `/Videos//stream.` endpoints which are present in the current…

  • CVE-2023-30627CriApr 24, 2023
    risk 0.00cvss 9.0epss 0.01

    jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When…

  • CVE-2022-35910MedAug 19, 2022
    risk 0.00cvss 5.4epss 0.01

    In Jellyfin before 10.8, stored XSS allows theft of an admin access token.

Page 2 of 2