Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Tautulli — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Tautulli, with AI-generated Chinese analysis, references, and POCs.

This page documents the Common Weakness Enumerations associated with Tautulli, an open-source Python-based monitoring and notification tool for Plex Media Server. It aggregates security vulnerabilities identified in this specific media server management application, covering reported issues from its initial releases through recent updates to provide a comprehensive historical view of its security posture. Visitors can use this resource to track vendor advisories regarding Tautulli, understand the nature and impact of specific weakness classes affecting media management software, and look up the product's detailed vulnerability history to assess risk over time. The collected data includes technical descriptions, severity ratings, and remediation strategies where available, allowing security professionals and administrators to make informed decisions about patching and configuration. By centralizing this information, the page aims to improve transparency and facilitate faster response to emerging threats in the Plex ecosystem. Users interested in the security lifecycle of Tautulli will find a structured overview of known defects, helping them prioritize maintenance tasks and verify the integrity of their deployed instances against publicly disclosed flaws. This resource serves as a reference point for both automated scanning tools and manual security audits, ensuring that the evolving threat landscape for Tautulli is accurately recorded and accessible for ongoing risk management efforts within digital media infrastructure.

Vendor: Tautulli

CVE ID Title CVSS Severity Published
CVE-2026-43986 Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay CWE-918 9.9 Critical 2026-06-04
CVE-2026-43985 Taultulli has CSRF in /configUpdate via missing anti-CSRF and method restriction that allows admin credential takeover CWE-352 8.8 High 2026-06-04
CVE-2026-43984 Tautulli has stored XSS in logFile via guest-controlled log_js_errors input CWE-79 8.9 High 2026-06-04
CVE-2026-41065 Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter Custom Template Directory CWE-1336 - - 2026-06-04
CVE-2026-40605 Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API CWE-22 - - 2026-06-04
CVE-2026-32275 Tautulli: Unsanitized JSONP callback parameter allows cross-origin script injection and API key theft CWE-79 7.6 - 2026-03-30
CVE-2026-31799 Tautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parameters CWE-89 4.9 Medium 2026-03-30
CVE-2026-31831 Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint CWE-23 7.5 - 2026-03-30
CVE-2026-31804 Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests through the Plex Media Server CWE-918 4.0 Medium 2026-03-30
CVE-2026-28505 Tautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whitelist check CWE-94 9.8 - 2026-03-30
CVE-2025-58763 Tautulli vulnerable to Authenticated Remote Code Execution via Command Injection CWE-78 8.1 High 2025-09-09
CVE-2025-58762 Tautulli vulnerable to Authenticated Remote Code Execution via write primitive and `Script` notification agent CWE-73 9.1 Critical 2025-09-09
CVE-2025-58761 Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy` CWE-27 8.6 High 2025-09-09
CVE-2025-58760 Tautulli vulnerable to Unauthenticated Path Traversal in `/image` endpoint CWE-23 8.6 High 2025-09-09

All 14 known CVE vulnerabilities affecting Tautulli with full Chinese analysis, references, and POCs where available.