VYPR
Vendor

Twonky

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2025-13315CriNov 19, 2025
    risk 0.69cvss 9.8epss 0.33

    Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

  • CVE-2025-13316HigNov 19, 2025
    risk 0.56cvss 8.1epss 0.03

    Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain…

  • CVE-2018-7203MedMar 30, 2018
    risk 0.43cvss 6.1epss 0.02

    Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.

  • CVE-2018-9182MedJun 8, 2018
    risk 0.40cvss 6.1epss 0.01

    Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.

  • CVE-2018-9177MedJun 8, 2018
    risk 0.40cvss 6.1epss 0.01

    Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.