Kodi is an open-source media-center application widely deployed across a range of consumer devices and platforms, presenting a modest but visible attack surface. Vulnerabilities affecting the product recur around input-handling and memory-safety weaknesses—including path traversal, buffer overflows, divide-by-zero conditions, cross-site scripting, and out-of-bounds writes—that reflect both its parsing demands and web-interface exposure. Public exploit code has frequently become available for this vendor's flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kodi over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5982HIGH Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, | Feb 28, 2017 | 7.5 | 83 | NO | YES |
CVE-2018-8831MEDIUM A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a | Apr 18, 2018 | 6.1 | 60 | NO | YES |
CVE-2017-8314MEDIUM Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles. | May 23, 2017 | 5.5 | 21 | NO | NO |
CVE-2021-42917MEDIUM Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper length of values passed to istream. | Nov 1, 2021 | 5.5 | 20 | NO | NO |
CVE-2023-30207MEDIUM A divide by zero issue discovered in Kodi Home Theater Software 19.5 and earlier allows attackers to cause a denial of service via use of crafted mp3 file. | Jul 5, 2023 | 5.5 | 18 | NO | NO |
CVE-2023-23082MEDIUM A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the off | Feb 3, 2023 | 4.6 | 18 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kodi.
Media articles that mention a CVE ID that affects a product developed by Kodi — matched by CVE ID, not by vendor name.