Search CVE reports


Toggle filters

11 – 20 of 26 results


CVE-2024-41665

Medium priority
Needs evaluation

Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic -...

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release
Show less packages

CVE-2024-28853

Medium priority
Needs evaluation

Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 allows a remote attacker to execute code via a crafted payload to...

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release
Show less packages

CVE-2024-28852

Medium priority
Needs evaluation

Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all forms in the Ampache that use `rule` as a variable are not secure. For example,...

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release
Show less packages

CVE-2023-0771

Medium priority
Vulnerable

SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2023-0606

Medium priority
Vulnerable

Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2022-4665

Medium priority
Vulnerable

Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2021-32644

Medium priority
Vulnerable

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to...

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-15153

Medium priority
Vulnerable

Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-21399

Medium priority
Vulnerable

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not...

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-12386

Medium priority
Fixed

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an...

1 affected package

ampache

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release
Show less packages