CVE-2026-45381
- EPSS 0.44%
- Veröffentlicht 21.09.2026 19:14:51
- Zuletzt bearbeitet 29.09.2026 15:17:25
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual escaping tha...
CVE-2026-49995
- EPSS 0.35%
- Veröffentlicht 21.09.2026 19:13:01
- Zuletzt bearbeitet 22.09.2026 14:17:13
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table is inserted by data/interfaces/default/newsletter_config.html into a JavaScript string without s...
CVE-2026-54915
- EPSS 0.21%
- Veröffentlicht 21.09.2026 19:09:55
- Zuletzt bearbeitet 24.09.2026 23:17:11
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes from the user-controlled redirect_uri parameter but leaves tab, l...
- EPSS 0.5%
- Veröffentlicht 21.09.2026 19:06:57
- Zuletzt bearbeitet 21.09.2026 20:17:26
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database in plexpy/webserve.py join the attacker-controlled config_file.filename or datab...
CVE-2026-43986
- EPSS 0.26%
- Veröffentlicht 04.06.2026 14:33:36
- Zuletzt bearbeitet 22.07.2026 20:10:00
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public `/image/<hash>` route that resolves attacker-controlled entries from `image_hash_lookup` and replays them through the same server-...
CVE-2026-43985
- EPSS 0.15%
- Veröffentlicht 04.06.2026 14:32:29
- Zuletzt bearbeitet 22.07.2026 20:10:00
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforce `POST` and does not use any anti-CSRF token. In t...
CVE-2026-43984
- EPSS 0.21%
- Veröffentlicht 04.06.2026 14:28:11
- Zuletzt bearbeitet 22.07.2026 20:10:00
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is enabled. The endpoint writes attacker-controlled stri...
CVE-2026-41065
- EPSS 0.43%
- Veröffentlicht 04.06.2026 14:17:13
- Zuletzt bearbeitet 22.07.2026 20:10:00
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On a fresh install before the setup wizard is comple...
CVE-2026-40605
- EPSS 0.3%
- Veröffentlicht 04.06.2026 12:50:10
- Zuletzt bearbeitet 22.07.2026 20:10:00
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache p...
CVE-2026-32275
- EPSS 0.34%
- Veröffentlicht 30.03.2026 19:43:06
- Zuletzt bearbeitet 02.04.2026 15:38:25
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-origin script injection and API key theft. This issue has been patched i...