Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Emby

First CVE: Oct 10, 2020Active for: 6 yearsTotal CVEs: 9

Emby is a media server and streaming platform whose vulnerabilities, though concentrated in a single product line, have skewed strongly toward critical-severity outcomes across web-interface and authentication attack surfaces. The recurring exposure clusters around input-handling and output-encoding weaknesses such as cross-site scripting and HTTP request smuggling, as well as authentication-bypass and access-control flaws that reflect the security demands of an internet-exposed media service. Vulnerabilities in this product frequently acquire public exploit code; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Emby over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2020
5 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-26948CRITICAL
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
Oct 10, 20209.889NOYES
CVE-2023-33193CRITICAL
Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad
May 30, 20239.138NOYES
CVE-2025-64113CRITICAL
Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration,
Dec 9, 20259.832NONO
CVE-2025-64325CRITICAL
Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Em
Nov 18, 20259.029NONO
CVE-2021-25827CRITICAL
Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.
Jun 28, 20239.827NONO
CVE-2021-32833HIGH
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to ex
Sep 9, 20218.627NONO
CVE-2021-25828MEDIUM
Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web.
Jun 28, 20236.119NONO
CVE-2023-4167MEDIUM
A vulnerability was found in Media Browser Emby Server 4.7.13.0 and classified as problematic. This issue affects some unknown processing of the file /web/. The manipulation leads
Aug 5, 20236.117NONO
CVE-2022-36223MEDIUM
In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administ
Dec 16, 20226.117NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
11%
56%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (55.6%)
Unknown0 (0.0%)
Required4 (44.4%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
11.1% of CVEs· 98th percentile
Nuclei
2 CVEs
22.2% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Emby.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Emby — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Emby's Products

View all 3 CNAs →

Top CWEs