Known Vulnerabilities for products from Subsonic
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Subsonic".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49340 json | Not Provided | 2026-06-19 | 2026-06-22 | |
| CVE-2026-49339 json | Not Provided | 2026-06-19 | 2026-06-22 | |
| CVE-2026-49338 json | Not Provided | 2026-06-19 | 2026-06-23 | |
| CVE-2018-20228 json | Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. | 8 - HIGH | 2018-12-19 | 2019-01-24 |
| CVE-2018-15898 json | The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificat... | 5.9 - MEDIUM | 2018-09-11 | 2018-11-30 |
| CVE-2018-14691 json | An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulnerabil... | 6.1 - MEDIUM | 2018-09-21 | 2018-11-09 |
| CVE-2018-14690 json | An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerabiliti... | 6.1 - MEDIUM | 2018-09-21 | 2018-11-09 |
| CVE-2018-14689 json | An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vulnerab... | 6.1 - MEDIUM | 2018-09-21 | 2018-11-09 |
| CVE-2018-14688 json | An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerabiliti... | 6.1 - MEDIUM | 2018-09-21 | 2018-11-09 |
| CVE-2018-9282 json | An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnera... | 6.1 - MEDIUM | 2018-09-21 | 2018-11-09 |
| CVE-2018-6014 json | Subsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve se... | 6.5 - MEDIUM | 2018-01-23 | 2018-02-13 |
| CVE-2017-9415 json | Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target userna... | Not Provided | 2017-07-21 | 2025-04-20 |
| CVE-2017-9414 json | Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers... | 8.8 - HIGH | 2018-02-05 | 2018-02-23 |
| CVE-2017-9413 json | Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to... | Not Provided | 2017-07-25 | 2025-04-20 |
| CVE-2017-9355 json | XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to cond... | Not Provided | 2017-06-07 | 2025-04-20 |
Known software with vulnerabilities from Subsonic
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Subsonic | Music Streamer | 4.4 |
| Application | Subsonic | Subsonic | 0.1 |