Ampache is a self-hosted digital media server and streaming platform whose vulnerability profile centers on web application security issues in its core product. The exposure recurs through weakness classes typical of web-facing applications: cross-site scripting, cross-site request forgery, SQL injection, and authentication flaws that arise from the challenge of securing user-controlled input and session management in a streaming interface. A meaningful share of the vendor's disclosures reach serious severity, reflecting the direct impact these classes can have on user data confidentiality and server integrity. Defenders deploying Ampache should prioritize keeping the application updated and restrict network exposure; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ampache over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4665HIGH Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6. | Dec 23, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-51490CRITICAL Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom UR | Nov 11, 2024 | 9.0 | 27 | NO | NO |
CVE-2019-12385HIGH An issue was discovered in Ampache through 3.9.1. The search engine is affected by a SQL Injection, so any user able to perform lib/class/search.class.php searches (even guest user | Aug 22, 2019 | 8.8 | 26 | NO | NO |
CVE-2017-18375HIGH Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php. | May 24, 2019 | 8.8 | 26 | NO | NO |
CVE-2020-15153CRITICAL Ampache before version 4.2.2 allows unauthenticated users to perform SQL injection. Refer to the referenced GitHub Security Advisory for details and a workaround. This is fixed in | Apr 30, 2021 | 9.8 | 24 | NO | NO |
CVE-2021-21399HIGH Ampache is a web based audio/video streaming application and file manager. Versions prior to 4.4.1 allow unauthenticated access to Ampache using the subsonic API. To successfully m | Apr 13, 2021 | 7.5 | 24 | NO | NO |
CVE-2024-51486HIGH Ampache is a web based audio/video streaming application and file manager. The vulnerability exists in the interface section of the Ampache menu, where users can change the "Custom | Nov 11, 2024 | 8.4 | 22 | NO | NO |
CVE-2023-0771HIGH SQL Injection in GitHub repository ampache/ampache prior to 5.5.7,develop. | Feb 10, 2023 | 8.8 | 22 | NO | NO |
CVE-2024-51487HIGH Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or dea | Nov 11, 2024 | 8.1 | 21 | NO | NO |
CVE-2024-51485HIGH Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing fails to properly validate CSRF tokens when activating or dea | Nov 11, 2024 | 8.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ampache.
Media articles that mention a CVE ID that affects a product developed by Ampache — matched by CVE ID, not by vendor name.