Vulnerabilities
Vulnerable Software
Emby:  >> Emby  Security Vulnerabilities
Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.
CVSS Score
9.8
EPSS Score
0.003
Published
2023-06-28
Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web.
CVSS Score
6.1
EPSS Score
0.002
Published
2023-06-28
In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administrator account.
CVSS Score
6.1
EPSS Score
0.001
Published
2022-12-16
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
CVSS Score
9.8
EPSS Score
0.9
Published
2020-10-10


Contact Us

Shodan ® - All rights reserved