Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jellyfin CRITICAL 9.1
CVE-2026-35033

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe…

Fix: 10.11.7+
Fix from $2,300 2026-04-14
Jellyfin HIGH 8.8
CVE-2026-35031

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /V…

Fix: 10.11.7+
Fix from $1,950 2026-04-14
Jellyfin HIGH 8.1
CVE-2026-35032

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /…

Fix: 10.11.7+
Fix from $1,950 2026-04-14
Jellyfin MEDIUM 6.5
CVE-2026-35034

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creati…

Fix: 10.11.7+
Fix from $1,600 2026-04-14
Jellyfin CRITICAL 9.8
CVE-2026-31852

Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut…

Patch available
Fix from $2,300 2026-03-11
Jellyfin HIGH 8.8
CVE-2025-31499

Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to…

Fix: 10.10.7+
Fix from $1,950 2025-04-15
Jellyfin HIGH 7.5
CVE-2025-32012

Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint provides administrators the a…

Fix: 10.10.7+
Fix from $1,950 2025-04-15
Jellyfin MEDIUM 5.4
CVE-2024-43801

Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack again…

Fix: after 10.9.10
Fix from $1,600 2024-09-02
Jellyfin HIGH 7.2
CVE-2023-48702

Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file …

Fix: 10.8.13+
Fix from $1,950 2023-12-13
Jellyfin HIGH 8.8
CVE-2023-49096

Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosControlle…

Fix: 10.8.13+
Fix from $1,950 2023-12-06
Jellyfin HIGH 8.1
CVE-2023-30626

Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability insid…

Fix: 10.8.10+
Fix from $1,950 2023-04-24
Jellyfin MEDIUM 5.4
CVE-2023-30627

jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-si…

Fix: 10.8.10+
Fix from $1,600 2023-04-24
Jellyfin HIGH 7.5
CVE-2023-27161

Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows atta…

Fix: after 10.7.7
Fix from $1,950 2023-03-10
Jellyfin MEDIUM 5.4
CVE-2023-23635

In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the loca…

Fix: after 10.8.3
Fix from $1,600 2023-02-03
Jellyfin MEDIUM 5.4
CVE-2023-23636

In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localS…

Fix: after 10.8.3
Fix from $1,600 2023-02-03
Jellyfin HIGH 8.8
CVE-2022-35909

In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality.

Fix: 10.8+
Fix from $1,950 2022-08-19
Jellyfin MEDIUM 5.4
CVE-2022-35910

In Jellyfin before 10.8, stored XSS allows theft of an admin access token.

Fix: 10.8+
Fix from $1,600 2022-08-19
Jellyfin MEDIUM 5.8
CVE-2021-29490EPSS 70%

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 v…

Fix: 10.7.3+
Fix from $1,600 2021-05-06
Jellyfin MEDIUM 6.5
CVE-2021-21402EPSS 80%

Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file …

Fix: 10.7.1+
Fix from $1,600 2021-03-23