Sabnzbd is a narrowly scoped Usenet download client and media automation application whose disclosed vulnerabilities concentrate in code-injection and OS-command-injection weaknesses that are typical of scripting-based automation tools handling untrusted input. The exposure also reflects path-traversal risks inherent to file-handling operations in media processing workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sabnzbd over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34237CRITICAL SABnzbd is an open source automated Usenet download tool. A design flaw was discovered in SABnzbd that could allow remote code execution. Manipulating the Parameters setting in the | Jun 7, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-13124HIGH SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on th | Aug 11, 2020 | 8.8 | 23 | NO | NO |
CVE-2021-29488MEDIUM SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.renamer()` function into writing downloaded files outside th | May 7, 2021 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sabnzbd.
Media articles that mention a CVE ID that affects a product developed by Sabnzbd — matched by CVE ID, not by vendor name.