📦 Jellyfin

by Jellyfin

🔍 What is Jellyfin?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-30627

CRITICAL CVSS 9.0 Apr 24, 2023

A stored cross-site scripting (XSS) vulnerability in jellyfin-web allows attackers to make arbitrary REST API calls with admin privileges. When combined with CVE-2023-30626, this can lead to remote co...

CVE-2025-31499

HIGH CVSS 8.8 Apr 15, 2025

This vulnerability allows argument injection in Jellyfin's FFmpeg processing, which can lead to arbitrary file write and potentially remote code execution. Attackers with low-privileged user credentia...

CVE-2023-48702

HIGH CVSS 7.2 Dec 13, 2023

This vulnerability allows a malicious administrator in Jellyfin to execute arbitrary code on the server by exploiting a path traversal issue in the media encoder configuration endpoint. Attackers can ...

CVE-2023-49096

HIGH CVSS 7.7 Dec 6, 2023

Jellyfin media server has an argument injection vulnerability in video/audio streaming endpoints that allows unauthenticated attackers to inject malicious arguments into FFmpeg commands. This could le...

CVE-2024-43801

MEDIUM CVSS 4.6 Sep 2, 2024

Jellyfin's user profile image upload accepts SVG files that can contain malicious JavaScript. When an admin user views such an image outside the Jellyfin Web UI (e.g., via browser 'view image'), the s...