Emby is a media server and streaming platform whose vulnerabilities, though concentrated in a single product line, have skewed strongly toward critical-severity outcomes across web-interface and authentication attack surfaces. The recurring exposure clusters around input-handling and output-encoding weaknesses such as cross-site scripting and HTTP request smuggling, as well as authentication-bypass and access-control flaws that reflect the security demands of an internet-exposed media service. Vulnerabilities in this product frequently acquire public exploit code; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emby over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-26948CRITICAL Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter. | Oct 10, 2020 | 9.8 | 89 | NO | YES |
CVE-2023-33193CRITICAL Emby Server is a user-installable home media server which stores and organizes a user's media files of virtually any format and makes them available for viewing at home and abroad | May 30, 2023 | 9.1 | 38 | NO | YES |
CVE-2025-64113CRITICAL Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrative access to an Emby Server (for Emby Server administration, | Dec 9, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-64325CRITICAL Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Em | Nov 18, 2025 | 9.0 | 29 | NO | NO |
CVE-2021-25827CRITICAL Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address. | Jun 28, 2023 | 9.8 | 27 | NO | NO |
CVE-2021-32833HIGH Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there is a set of arbitrary file read vulnerabilities. This vulnerability is known to ex | Sep 9, 2021 | 8.6 | 27 | NO | NO |
CVE-2021-25828MEDIUM Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web. | Jun 28, 2023 | 6.1 | 19 | NO | NO |
CVE-2023-4167MEDIUM A vulnerability was found in Media Browser Emby Server 4.7.13.0 and classified as problematic. This issue affects some unknown processing of the file /web/. The manipulation leads | Aug 5, 2023 | 6.1 | 17 | NO | NO |
CVE-2022-36223MEDIUM In Emby Server 4.6.7.0, the playlist name field is vulnerable to XSS stored where it is possible to steal the administrator access token and flip or steal the media server administ | Dec 16, 2022 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emby.
Media articles that mention a CVE ID that affects a product developed by Emby — matched by CVE ID, not by vendor name.