CVE-2024-41665
- EPSS 0.32%
- Published 23.07.2024 18:15:06
- Last modified 03.02.2025 15:33:40
Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic - Configure Democratic Playlist" featu...
CVE-2024-28852
- EPSS 0.77%
- Published 27.03.2024 14:15:10
- Last modified 05.02.2025 21:20:47
Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all forms in the Ampache that use `rule` as a variable are not secure. For example, when querying a song, w...
CVE-2024-28853
- EPSS 0.49%
- Published 27.03.2024 14:15:10
- Last modified 15.01.2025 17:52:58
Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 allows a remote attacker to execute code via a crafted payload to serval parameters in the post reques...
CVE-2023-0771
- EPSS 0.11%
- Published 10.02.2023 01:15:10
- Last modified 21.11.2024 07:37:47
SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.
CVE-2023-0606
- EPSS 0.15%
- Published 01.02.2023 01:15:08
- Last modified 21.11.2024 07:37:28
Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.
CVE-2022-4665
- EPSS 0.09%
- Published 23.12.2022 01:15:10
- Last modified 21.11.2024 07:35:41
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.
CVE-2021-32644
- EPSS 0.44%
- Published 22.06.2021 18:15:08
- Last modified 21.11.2024 06:07:26
Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php p...
CVE-2020-15153
- EPSS 2.56%
- Published 30.04.2021 16:15:07
- Last modified 21.11.2024 05:04:57
Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.
CVE-2021-21399
- EPSS 0.14%
- Published 13.04.2021 20:15:14
- Last modified 21.11.2024 05:48:16
Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not part of the site to...
CVE-2019-12386
- EPSS 0.25%
- Published 22.08.2019 19:15:14
- Last modified 21.11.2024 04:22:43
An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an admin to create a ne...