Jellyfin
by Jellyfin
Source repositories
CVEs (23)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-49096 | Hig | 0.00 | 7.7 | 0.01 | Dec 6, 2023 | Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos//stream` and `/Videos//stream.` endpoints which are present in the current… | ||
| CVE-2023-30627 | Cri | 0.00 | 9.0 | 0.01 | Apr 24, 2023 | jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When… | ||
| CVE-2022-35910 | Med | 0.00 | 5.4 | 0.01 | Aug 19, 2022 | In Jellyfin before 10.8, stored XSS allows theft of an admin access token. |
- risk 0.00cvss 7.7epss 0.01
Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosController, specifically the `/Videos//stream` and `/Videos//stream.` endpoints which are present in the current…
- risk 0.00cvss 9.0epss 0.01
jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-site scripting vulnerability in device.js can be used to make arbitrary calls to the `REST` endpoints with admin privileges. When…
- risk 0.00cvss 5.4epss 0.01
In Jellyfin before 10.8, stored XSS allows theft of an admin access token.
Page 2 of 2