CVE-2026-27793
- EPSS 0.03%
- Veröffentlicht 27.02.2026 19:38:49
- Zuletzt bearbeitet 04.03.2026 16:47:37
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.1.0, the `GET /api/v1/user/:id` endpoint returns the full settings object for any user, including Pushover, Pushbullet, and Telegram credenti...
CVE-2026-27792
- EPSS 0.01%
- Veröffentlicht 27.02.2026 19:33:18
- Zuletzt bearbeitet 04.03.2026 16:49:30
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenticated users...
CVE-2026-27707
- EPSS 0.04%
- Veröffentlicht 27.02.2026 19:29:18
- Zuletzt bearbeitet 04.03.2026 16:54:47
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an authentication guard logic flaw in `POST /api/v1/auth/jellyfin` allows an unauthenticated attacker to r...