Plex Media Server

6 known vulnerabilities in Plex Media Server, 1 actively exploited, with patch priority, exploit likelihood and the news covering them.

Recently exploited

  • CVE-2020-5741 CVSS 7.2 high · actively exploited Plex Media Server Remote Code Execution Vulnerability

Latest vulnerabilities

  • CVE-2026-96656 CVSS 8.6 high Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference…
  • CVE-2026-96655 CVSS 5.3 medium Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the…
  • CVE-2026-96654 CVSS 6.9 medium Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other…
  • CVE-2026-96652 CVSS 5.3 medium Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL…
  • CVE-2026-96651 CVSS 7.1 high Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path…
  • CVE-2020-5741 CVSS 7.2 high · actively exploited Plex Media Server Remote Code Execution Vulnerability