Total
6 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-58763 | 1 Tautulli | 1 Tautulli | 2025-09-18 | N/A | 8.0 HIGH |
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with administrative privileges to obtain remote code execution on the application server. This vulnerability requires the application to have been cloned from GitHub and installed manually. When Tautulli is cloned directly from GitHub and installed manually, the application manages updates and versioning through calls to the `git` command ...
Show More |
|||||
| CVE-2025-58760 | 1 Tautulli | 1 Tautulli | 2025-09-18 | N/A | 8.6 HIGH |
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.15.3 and earlier is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. In Tautulli, the `/image` API endpoint is used to serve static images from the application's data directory to users. This endpoint can be accessed without authentication, and its intended purpose is for server background images ...
Show More |
|||||
| CVE-2025-58761 | 1 Tautulli | 1 Tautulli | 2025-09-18 | N/A | 8.6 HIGH |
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 and prior is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. The `real_pms_image_proxy` is used to fetch an image directly from the backing Plex Media Server. The image to be fetched is specified through an `img` URL parameter, which can either be a URL or a file path. There is som ...
Show More |
|||||
| CVE-2025-58762 | 1 Tautulli | 1 Tautulli | 2025-09-18 | N/A | 9.1 CRITICAL |
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_image_proxy` endpoint to write arbitrary python scripts into the application filesystem. This leads to remote code execution when combined with the `Script` notification agent. If an attacker with administrative access changes the URL of the PMS to a server they control, they can then abuse the `pms_image_proxy` to obtain a file w ...
Show More |
|||||
| CVE-2019-8939 | 1 Tautulli | 1 Tautulli | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
|
data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.
|
|||||
| CVE-2019-19833 | 1 Tautulli | 1 Tautulli | 2024-11-21 | 4.3 MEDIUM | 6.5 MEDIUM |
|
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a user login area).
|
|||||