Streaming Engine
Wowza · 26 CVEs
Wowza Streaming Engine 4.5.0 Multiple Cross-Site Scripting Vulnerabilities
Mar 15, 2026
Wowza Streaming Engine 4.5.0 CSRF via user edit endpoint
Mar 15, 2026
Wowza Streaming Engine 4.5.0 Privilege Escalation via user edit
Mar 15, 2026
Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe
Mar 15, 2026
Application Delete Path Traversal in Wowza Streaming Engine
Nov 21, 2024
Application Copy Path Traversal in Wowza Streaming Engine
Nov 21, 2024
Application Creation Path Traversal in Wowza Streaming Engine
Nov 21, 2024
Stored Cross-Site Scripting in Wowza Streaming Engine
Nov 21, 2024
Stream Target Remote Code Execution in Wowza Streaming Engine
Nov 21, 2024
Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources v…
Oct 5, 2021
A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker t…
Oct 5, 2021
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.pas…
Apr 23, 2021
Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files…
Apr 23, 2021
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in…
Aug 3, 2020
Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license…
Aug 3, 2020
A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza…
May 18, 2020
An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue…
May 18, 2020
A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-o…
Apr 14, 2020
Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.…
Jan 29, 2020
A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to…
Jan 29, 2020
Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by…
Jan 29, 2020
The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via…
Mar 18, 2019
In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the direct…
Mar 5, 2018
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (co…
Mar 1, 2018
An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a…
Mar 1, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2016-20036 | Wowza Streaming Engine 4.5.0 Multiple Cross-Site Scripting Vulnerabilities | MEDIUM | 0.24% | Mar 15, 2026 |
| CVE-2016-20035 | Wowza Streaming Engine 4.5.0 CSRF via user edit endpoint | MEDIUM | 0.16% | Mar 15, 2026 |
| CVE-2016-20034 | Wowza Streaming Engine 4.5.0 Privilege Escalation via user edit | HIGH | 0.21% | Mar 15, 2026 |
| CVE-2016-20033 | Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe | HIGH | 0.21% | Mar 15, 2026 |
| CVE-2024-52056 | Application Delete Path Traversal in Wowza Streaming Engine | MEDIUM | 0.71% | Nov 21, 2024 |
| CVE-2024-52055 | Application Copy Path Traversal in Wowza Streaming Engine | HIGH | 1.00% | Nov 21, 2024 |
| CVE-2024-52054 | Application Creation Path Traversal in Wowza Streaming Engine | MEDIUM | 0.75% | Nov 21, 2024 |
| CVE-2024-52053 | Stored Cross-Site Scripting in Wowza Streaming Engine | HIGH | 0.66% | Nov 21, 2024 |
| CVE-2024-52052 | Stream Target Remote Code Execution in Wowza Streaming Engine | CRITICAL | 0.50% | Nov 21, 2024 |
| CVE-2021-35492 | Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/vhost/histo… | MEDIUM | 3.34% | Oct 5, 2021 |
| CVE-2021-35491 | A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginem… | HIGH | 0.88% | Oct 5, 2021 |
| CVE-2021-31539 | Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able… | MEDIUM | 0.30% | Apr 23, 2021 |
| CVE-2021-31540 | Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regular local… | HIGH | 0.39% | Apr 23, 2021 |
| CVE-2019-19455 | Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine /… | HIGH | 0.37% | Aug 3, 2020 |
| CVE-2019-19453 | Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a malicious pa… | MEDIUM | 0.81% | Aug 3, 2020 |
| CVE-2019-19456 | A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue w… | MEDIUM | 1.00% | May 18, 2020 |
| CVE-2019-19454 | An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine… | HIGH | 1.55% | May 18, 2020 |
| CVE-2020-9004 | A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to the admini… | HIGH | 3.53% | Apr 14, 2020 |
| CVE-2019-7655 | Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/server/serv… | MEDIUM | 0.95% | Jan 29, 2020 |
| CVE-2019-7656 | A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. The install… | HIGH | 0.45% | Jan 29, 2020 |
| CVE-2019-7654 | Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be tricked into ma… | MEDIUM | 0.85% | Jan 29, 2020 |
| CVE-2018-19365 | The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafted HTTP req… | CRITICAL | 22.29% | Mar 18, 2019 |
| CVE-2017-16922 | In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directory structure and retrieval of a file ar… | MEDIUM | 1.42% | Mar 5, 2018 |
| CVE-2018-7049 | An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderMediaList a… | MEDIUM | 0.88% | Mar 1, 2018 |
| CVE-2018-7048 | An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request. | HIGH | 1.49% | Mar 1, 2018 |
Showing 1 to 25 of 26 CVEs