📦 Ampache

by Ampache

🔍 What is Ampache?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-21399

CRITICAL CVSS 9.1 Apr 13, 2021

CVE-2021-21399 is an authentication bypass vulnerability in Ampache's Subsonic API that allows unauthenticated attackers to access the application using a non-existent username. This affects all Ampac...

CVE-2024-51484

HIGH CVSS 8.1 Nov 11, 2024

Ampache versions before 7.0.1 have a CSRF vulnerability in token parsing when activating/deactivating controllers, allowing attackers to trick authenticated administrators into performing unauthorized...

CVE-2024-51487

HIGH CVSS 8.1 Nov 11, 2024

Ampache versions before 7.0.1 have a CSRF vulnerability in catalog activation/deactivation functions. Attackers can trick authenticated administrators into performing unauthorized catalog management a...

CVE-2024-51486

MEDIUM CVSS 5.5 Nov 11, 2024

This is a stored cross-site scripting (XSS) vulnerability in Ampache's interface configuration that allows authenticated users to inject malicious JavaScript into the favicon URL field. When other use...

CVE-2024-51489

MEDIUM CVSS 5.4 Nov 11, 2024

Ampache's CSRF token validation flaw allows attackers to forge cross-site request forgery attacks. This enables sending messages to any user, including administrators, via malicious requests. All Ampa...

CVE-2024-41665

MEDIUM CVSS 5.5 Jul 23, 2024

Ampache versions before 6.6.0 contain a stored cross-site scripting (XSS) vulnerability in the Democratic Playlist configuration feature. An attacker with Content Manager permissions can inject malici...