Bazarr is a subtitle-management application for media libraries that operates as a self-hosted service, and its vulnerability profile centers on improper path traversal and server-side request forgery weaknesses characteristic of web-service input handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bazarr over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-40348HIGH An issue in the component /api/swaggerui/static of Bazaar v1.4.3 allows unauthenticated attackers to execute a directory traversal. | Jul 20, 2024 | 8.2 | 41 | NO | YES |
CVE-2023-50264HIGH Bazarr manages and downloads subtitles. Prior to 1.3.1, Bazarr contains an arbitrary file read in /system/backup/download/ endpoint in bazarr/app/ui.py does not validate the user-c | Dec 15, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-50265HIGH Bazarr manages and downloads subtitles. Prior to 1.3.1, the /api/swaggerui/static endpoint in bazarr/app/ui.py does not validate the user-controlled filename variable and uses it i | Dec 15, 2023 | 7.5 | 19 | NO | NO |
CVE-2023-50266MEDIUM Bazarr manages and downloads subtitles. In version 1.2.4, the proxy method in bazarr/bazarr/app/ui.py does not validate the user-controlled protocol and url variables and passes th | Dec 15, 2023 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bazarr.
Media articles that mention a CVE ID that affects a product developed by Bazarr — matched by CVE ID, not by vendor name.