Subsonic is a self-hosted music streaming application that attracts vulnerability disclosures centered on web application security and configuration issues. Its vulnerability profile clusters around cross-site scripting, cross-site request forgery, server-side request forgery, sensitive information exposure, and improper certificate validation—weaknesses typical of web-facing services where input handling and trust boundaries define the attack surface, and public exploit code frequently becomes available for these classes. Live severity, exploitation status, and current exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Subsonic over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9355HIGH XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a cr | Jun 7, 2017 | 7.4 | 48 | NO | YES |
CVE-2017-9414HIGH Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims fo | Feb 5, 2018 | 8.8 | 46 | NO | YES |
CVE-2017-9413HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that ( | Jul 25, 2017 | 8.8 | 37 | NO | YES |
CVE-2017-9415HIGH Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests t | Jul 21, 2017 | 7.5 | 35 | NO | YES |
CVE-2018-20228HIGH Subsonic V6.1.5 allows internetRadioSettings.view streamUrl CSRF, with resultant SSRF. | Dec 19, 2018 | 8.0 | 25 | NO | NO |
CVE-2018-9282MEDIUM An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnerability in the add parameter to podcastReceiverAdmin.vie | Sep 21, 2018 | 6.1 | 22 | NO | NO |
CVE-2018-14691MEDIUM An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulnerabilities in the c0-param2, c0-param3, and c0-param4 parame | Sep 21, 2018 | 6.1 | 22 | NO | NO |
CVE-2018-14690MEDIUM An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerabilities in the title and subtitle parameters to generalSetti | Sep 21, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-14689MEDIUM An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vulnerabilities in the name[x], sourceformats[x], targetFormat[ | Sep 21, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-14688MEDIUM An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerabilities in the name[x], streamUrl[x], homepageUrl[x] paramet | Sep 21, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Subsonic.
Media articles that mention a CVE ID that affects a product developed by Subsonic — matched by CVE ID, not by vendor name.