CVE-2026-100847
- EPSS 0.26%
- Veröffentlicht 27.09.2026 01:28:41
- Zuletzt bearbeitet 30.09.2026 16:17:02
AzuraCast before 0.23.8 contains a DQL injection vulnerability in the sortOrder API parameter of AbstractSearchableListAction.php. Attackers can inject arbitrary DQL expressions through the sortOrder parameter to extract sensitive database informatio...
CVE-2026-76836
- EPSS 0.33%
- Veröffentlicht 24.08.2026 17:36:01
- Zuletzt bearbeitet 24.09.2026 20:43:32
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{...
CVE-2026-67917
- EPSS 0.23%
- Veröffentlicht 17.08.2026 00:00:00
- Zuletzt bearbeitet 09.09.2026 16:04:24
zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanit...
CVE-2026-42605
- EPSS 0.83%
- Veröffentlicht 09.05.2026 19:44:05
- Zuletzt bearbeitet 24.07.2026 19:10:00
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}/files/upload) is not sanitized for path traversal ...
CVE-2026-42606
- EPSS 0.48%
- Veröffentlicht 09.05.2026 19:43:35
- Zuletzt bearbeitet 24.07.2026 19:10:00
AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with no trusted proxy allowlist. An unauthenticated att...
CVE-2025-67737
- EPSS 0.24%
- Veröffentlicht 12.12.2025 06:53:15
- Zuletzt bearbeitet 17.02.2026 14:52:29
AzuraCast is a self-hosted, all-in-one web radio management suite. Versions 0.23.1 mistakenly include an API endpoint that is intended for internal use by the SFTP software sftpgo, exposing it to the public-facing HTTP API for AzuraCast installations...
CVE-2023-2531
- EPSS 0.79%
- Veröffentlicht 05.05.2023 01:15:08
- Zuletzt bearbeitet 21.11.2024 07:58:47
Improper Restriction of Excessive Authentication Attempts in GitHub repository azuracast/azuracast prior to 0.18.3.
CVE-2023-2191
- EPSS 0.5%
- Veröffentlicht 20.04.2023 02:15:06
- Zuletzt bearbeitet 21.11.2024 07:58:06
Cross-site Scripting (XSS) - Stored in GitHub repository azuracast/azuracast prior to 0.18.