Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tautulli CRITICAL 9.1
CVE-2026-32275

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP cal…

Fix: 2.17.0+
Fix from $2,300 2026-03-30
Tautulli HIGH 7.5
CVE-2026-31831

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is …

Fix: 2.17.0+
Fix from $1,950 2026-03-30
Tautulli MEDIUM 5.3
CVE-2026-31804

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-…

Fix: 2.17.0+
Fix from $1,600 2026-03-30
Tautulli CRITICAL 10.0
CVE-2026-28505

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handl…

Fix: 2.17.0+
Fix from $2,300 2026-03-30
Tautulli HIGH 7.2
CVE-2025-58763

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows…

Fix: 2.16.0+
Fix from $1,950 2025-09-09
Tautulli HIGH 7.5
CVE-2025-58760

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.15.3 and earlier is vulnerabl…

Fix: 2.16.0+
Fix from $1,950 2025-09-09
Tautulli HIGH 7.5
CVE-2025-58761

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 and prior is v…

Fix: 2.16.0+
Fix from $1,950 2025-09-09
Tautulli HIGH 7.2
CVE-2025-58762

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative acces…

Fix: 2.16.0+
Fix from $1,950 2025-09-09
Tautulli MEDIUM 6.5
CVE-2019-19833EPSS 15%

In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in appl…

No fix yet
Fix from $1,600 2019-12-18
Tautulli MEDIUM 6.1
CVE-2019-8939

data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.

Patch available
Fix from $1,600 2019-02-19