Plex / Media Server
14 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-96656 | Plex Media Server arbitrary file write | HIGH | 8.6 | Sep 23, 2026 |
| CVE-2026-96655 | Plex Media Server arbitrary-host SSRF | MEDIUM | 5.3 | Sep 23, 2026 |
| CVE-2026-96654 | Plex Media Server URL injection | MEDIUM | 6.9 | Sep 23, 2026 |
| CVE-2026-96652 | Plex Media Server SSRF | MEDIUM | 5.3 | Sep 23, 2026 |
| CVE-2026-96651 | Plex Media Server path traversal | HIGH | 7.1 | Sep 23, 2026 |
| CVE-2025-69417 | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via… | MEDIUM | 5.0 | Jan 2, 2026 |
| CVE-2025-69416 | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via… | MEDIUM | 5.0 | Jan 2, 2026 |
| CVE-2025-69415 | In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is curre… | HIGH | 7.1 | Jan 2, 2026 |
| CVE-2025-69414 | Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token. | HIGH | 8.5 | Jan 2, 2026 |
| CVE-2025-34158 | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the… | HIGH | 8.5 | Aug 21, 2025 |
| CVE-2021-33959 | Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service. | HIGH | 7.5 | Jan 18, 2023 |
| CVE-2021-42835 | An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can a… | HIGH | 7.0 | Dec 8, 2021 |
| CVE-2020-5742 | Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests. | HIGH | 8.8 | Jun 15, 2020 |
| CVE-2020-5741 KEV | Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | HIGH | 7.2 | May 8, 2020 |
| CVE-2020-5740 | Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges. | HIGH | 7.8 | Apr 22, 2020 |
| CVE-2019-19141 | The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the… | HIGH | 8.8 | Dec 19, 2019 |
| CVE-2018-21031 | Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and ca… | MEDIUM | 6.5 | Nov 18, 2019 |
| CVE-2018-13415 | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, u… | CRITICAL | 9.8 | Aug 13, 2018 |
| CVE-2014-9304 | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions… | HIGH | 7.5 | Dec 7, 2014 |
| CVE-2014-9181 | Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI t… | MEDIUM | 5.0 | Dec 2, 2014 |
Showing 1 to 14 of 14 CVEs