Leepeuker maintains a focused portfolio centered on the Movary media-tracking application, which has attracted attention despite modest product breadth. The recurring vulnerability pattern reflects common application-layer weaknesses in web-facing software: improper input validation, cross-site scripting, open redirects, and authorization gaps that allow either unauthorized access or user-directed exploitation. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Leepeuker over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40350HIGH Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settin | Apr 18, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-40349HIGH Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator b | Apr 18, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-40348HIGH Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary int | Apr 18, 2026 | 7.7 | 25 | NO | NO |
CVE-2026-23841MEDIUM Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versio | Jan 19, 2026 | 6.1 | 23 | NO | NO |
CVE-2026-23840MEDIUM Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versio | Jan 19, 2026 | 6.1 | 23 | NO | NO |
CVE-2026-23839MEDIUM Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versio | Jan 19, 2026 | 6.1 | 23 | NO | NO |
CVE-2025-64115MEDIUM Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in mul | Oct 30, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-64116MEDIUM Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attackers | Oct 30, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Leepeuker.
Media articles that mention a CVE ID that affects a product developed by Leepeuker — matched by CVE ID, not by vendor name.