Search CVE reports


Toggle filters

11 – 20 of 26 results


CVE-2024-41665

Medium priority
Needs evaluation

Ampache, a web based audio/video streaming application and file manager, has a stored cross-site scripting (XSS) vulnerability in versions prior to 6.6.0. This vulnerability exists in the "Playlists - Democratic -...

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2024-28853

Medium priority
Needs evaluation

Ampache is a web based audio/video streaming application and file manager. Stored Cross Site Scripting (XSS) vulnerability in ampache before v6.3.1 allows a remote attacker to execute code via a crafted payload to...

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2024-28852

Medium priority
Needs evaluation

Ampache is a web based audio/video streaming application and file manager. Ampache has multiple reflective XSS vulnerabilities,this means that all forms in the Ampache that use `rule` as a variable are not secure. For example,...

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2023-0771

Medium priority
Vulnerable

SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop.

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2023-0606

Medium priority
Vulnerable

Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2022-4665

Medium priority
Vulnerable

Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release
Show less packages

CVE-2021-32644

Medium priority
Vulnerable

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to...

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release
Show less packages

CVE-2020-15153

Medium priority
Vulnerable

Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in version 4.2.2 and the development branch.

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release
Show less packages

CVE-2021-21399

Medium priority
Vulnerable

Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully make the attack you must use a username that is not...

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release Not in release Not in release
Show less packages

CVE-2019-12386

Medium priority
Fixed

An issue was discovered in Ampache through 3.9.1. A stored XSS exists in the localplay.php LocalPlay "add instance" functionality. The injected code is reflected in the instances menu. This vulnerability can be abused to force an...

1 affected package

ampache

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ampache Not in release Not in release
Show less packages