CVE-2026-33890
- EPSS 0.27%
- Veröffentlicht 27.03.2026 01:16:21
- Zuletzt bearbeitet 01.04.2026 13:44:03
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application expo...
CVE-2026-33935
- EPSS 0.39%
- Veröffentlicht 27.03.2026 01:16:21
- Zuletzt bearbeitet 01.04.2026 13:42:53
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor accounts from password-based authentication by triggering failed login attempts. The ...
CVE-2026-33735
- EPSS 0.04%
- Veröffentlicht 27.03.2026 01:16:20
- Zuletzt bearbeitet 31.03.2026 19:02:38
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the applic...
CVE-2026-24140
- EPSS 0.02%
- Veröffentlicht 23.01.2026 23:59:56
- Zuletzt bearbeitet 02.02.2026 13:26:17
MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the settings management functionality due to insufficient input validation. The application's saveSettings() f...
CVE-2026-24139
- EPSS 0.01%
- Veröffentlicht 23.01.2026 23:55:23
- Zuletzt bearbeitet 02.02.2026 13:26:40
MyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, allowing guest users to download the complete application database. The application fails to properly v...
CVE-2026-23848
- EPSS 0.16%
- Veröffentlicht 19.01.2026 20:34:40
- Zuletzt bearbeitet 02.02.2026 13:27:34
MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via `X-Forwarded-For` header spoofing allows unauthenticated attackers to bypass IP-based rate limiting on general API endpoints...
CVE-2026-23837
- EPSS 0.35%
- Veröffentlicht 19.01.2026 20:09:37
- Zuletzt bearbeitet 02.02.2026 13:24:34
MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to bypass the mandatory authentication check in the roleBasedAuthMiddlew...