Known Vulnerabilities for Media Server by Plex
Listed below are 10 of the newest known vulnerabilities associated with "Media Server" by "Plex".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-96656 json | Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The prefere... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96655 json | Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via th... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96654 json | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker ... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96652 json | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can includ... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-96651 json | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowi... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-94108 json | getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fails to ... | Not Provided | 2026-09-20 | 2026-09-21 |
| CVE-2026-93506 json | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/uploa... | Not Provided | 2026-09-18 | 2026-09-22 |
| CVE-2026-93505 json | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-servi... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-90901 json | Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1... | Not Provided | 2026-09-23 | 2026-09-23 |
| CVE-2026-86100 json | Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL... | Not Provided | 2026-09-05 | 2026-09-08 |