Known Vulnerabilities for Music by Apple
Listed below are 7 of the newest known vulnerabilities associated with "Music" by "Apple".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-104811 json | DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installati... | Not Provided | 2026-10-05 | 2026-10-05 |
| CVE-2026-104673 json | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player... | Not Provided | 2026-10-05 | 2026-10-05 |
| CVE-2026-101036 json | A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of ... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-93624 json | Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-82304 json | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, le... | Not Provided | 2026-09-05 | 2026-09-06 |
| CVE-2026-81289 json | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-78283 json | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-73662 json | FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line o... | Not Provided | 2026-08-13 | 2026-08-17 |
| CVE-2026-72605 json | A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user ... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-69110 json | OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to ... | Not Provided | 2026-08-04 | 2026-08-04 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apple | Music | 3.4.0 |