Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Plex

First CVE: Dec 2, 2014Active for: 12 yearsTotal CVEs: 15
73.3
VTI Score
TOP TARGET

Plex operates a media server platform widely deployed in home and small-business environments for streaming music, video, and photos, where its internet-facing nature and authentication mechanisms present a concentrated attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the vendor also carries a moderate tendency toward confirmed in-the-wild exploitation. The recurring exposure centers on authorization and access-control weaknesses—including improper authorization, path traversal, untrusted deserialization, and XXE—that reflect the challenges of building a feature-rich media-serving application with remote access. Current exploitation activity, severity distribution, and vulnerability counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
6.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Plex over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 2014
11 years ago
Most Recent CVE
Jan 2, 2026
203 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-5741HIGH
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
May 8, 20207.294YESYES
CVE-2018-13415CRITICAL
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attack
Aug 13, 20189.861NOYES
CVE-2025-34158HIGH
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the s
Aug 21, 20258.532NONO
CVE-2021-33959HIGH
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
Jan 18, 20237.531NONO
CVE-2014-9304HIGH
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted
Dec 7, 20147.531NOYES
CVE-2020-5742HIGH
Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.
Jun 15, 20208.828NONO
CVE-2019-19141HIGH
The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server ha
Dec 19, 20198.827NONO
CVE-2014-9181MEDIUM
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2)
Dec 2, 20145.026NOYES
CVE-2025-69414HIGH
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
Jan 2, 20267.125NONO
CVE-2025-69415HIGH
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with
Jan 2, 20267.124NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
27%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (13.3%)
Network11 (73.3%)
Unknown2 (13.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (80.0%)
High1 (6.7%)
Unknown2 (13.3%)
User Interaction
None12 (80.0%)
Unknown2 (13.3%)
Required1 (6.7%)
Privileges Required
Low9 (60.0%)
High1 (6.7%)
None3 (20.0%)
Unknown2 (13.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
1 CVE
6.7% of CVEs· 100th percentile
Metasploit
1 CVE
6.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
20.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Plex.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Plex — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Plex's Products

View all 2 CNAs →

Top CWEs