Plex
2 CVEs tracked since 2014. Since Dec 2014, none of them reached CISA KEV.
Plex CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2014-12 | 2 | 0 |
Products
The products that kept showing up in Plex's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Plex.
- CVE-2026-96656Plex Media Server arbitrary file write7.2
- CVE-2026-96655Plex Media Server arbitrary-host SSRF4.3
- CVE-2026-96654Plex Media Server URL injection6.5
- CVE-2026-96652Plex Media Server SSRF4.3
- CVE-2026-96651Plex Media Server path traversal6.5
- CVE-2025-69417In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.5.0
- CVE-2025-69416In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.5.0
- CVE-2025-69415In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.7.1
- CVE-2025-69414Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.8.5
- CVE-2025-34158Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and ...8.5
- CVE-2021-33959Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.7.5
- CVE-2021-42835An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the u...7.0
- CVE-2020-5742Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.8.8
- CVE-2020-5741Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.7.2
- CVE-2020-5740Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.7.8
The record
- Peak rank
- #87 in Dec 2014
- Busiest month shown
- Dec 2014, 2 CVEs
- Months with a KEV entry
- 0 since Dec 2014
- Monthly snapshots
- 1 since 2014