vendor

plex

9 thingsrelated by NVD
Severity

Its products

media server 9

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference…
CVE-2026-96656
Severity high
Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the…
CVE-2026-96655
Severity medium
Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other…
CVE-2026-96654
Severity medium
Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL…
CVE-2026-96652
Severity medium
Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path…
CVE-2026-96651
Severity high
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for…
CVE-2025-69417
Severity medium
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for…
CVE-2025-69416
Severity medium
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether…
CVE-2025-69415
Severity high
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient…
CVE-2025-69414
Severity high