Advplyr
4 CVEs tracked since 2023. Since Dec 2023, none of them reached CISA KEV.
Advplyr CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2023-12 | 4 | 0 |
Products
The products that kept showing up in Advplyr's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Advplyr.
- CVE-2026-73085Audiobookshelf: Refresh Token Accepted on Resource Endpoints—
- CVE-2026-71209audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal7.5
- CVE-2026-42888Audiobookshelf: Path Traversal vulnerability in the audiobookshelf project—
- CVE-2026-42887Audiobookshelf: Stored Cross-Site Scripting in Login Page Custom Message4.5
- CVE-2026-42886Audiobookshelf: Memory amplification DoS via oversized compressed details entry in backup upload4.9
- CVE-2026-42885Audiobookshelf: Path prefix bypass in filesystem existence check leaks out-of-scope file existence4.3
- CVE-2026-42884Audiobookshelf: Collection endpoints bypass library access controls exposing restricted library data4.3
- CVE-2026-42883Audiobookshelf: Cross-library file exfiltration via unscoped bulk download endpoint6.5
- CVE-2026-27974Audiobooksheld VUlnerable to Stored XSS in WrappingMarquee.js via Audiobook Metadata (Mobile App Audio Player)4.8
- CVE-2026-27963Audiobookshelf has Stored XSS in Tooltip.vue via Audiobook Metadata4.8
- CVE-2026-27973Audiobookshelf has Stored XSS in ItemSearchCard.vue via Audiobook Metadata (Search Results on Mobile App)4.0
- CVE-2025-57800Audiobookshelf vulnerable to OIDC token exfiltration and account takeover8.8
- CVE-2025-46338Audiobookshelf Vulnerable to Cross-Site-Scripting Reflected via POST Request in /api/upload6.1
- CVE-2025-25205Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching8.2
- CVE-2024-43797Path Traversal in audiobookshelf6.3
The record
- Peak rank
- #157 in Dec 2023
- Busiest month shown
- Dec 2023, 4 CVEs
- Months with a KEV entry
- 0 since Dec 2023
- Monthly snapshots
- 1 since 2023