Tautulli is a monitoring and analytics platform for Plex Media Server installations that sits at the intersection of web interface exposure and media-server privilege levels. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through web-application and file-handling weakness classes including cross-site scripting, cross-site request forgery, path traversal, code injection, and insecure file-name or path control that reflect the challenges of securing a third-party admin dashboard. Defenders should treat Tautulli instances, especially those reachable over the network, as requiring regular patching; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tautulli over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19833MEDIUM In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a use | Dec 18, 2019 | 6.5 | 36 | NO | YES |
CVE-2026-28505CRITICAL Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed ev | Mar 30, 2026 | 10.0 | 32 | NO | NO |
CVE-2026-32275CRITICAL Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-or | Mar 30, 2026 | 9.1 | 27 | NO | NO |
CVE-2026-31831HIGH Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, a | Mar 30, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-58763HIGH Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with administrative | Sep 9, 2025 | 7.2 | 24 | NO | NO |
CVE-2025-58761HIGH Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 and prior is vulnerable to path traversal, al | Sep 9, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-58760HIGH Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.15.3 and earlier is vulnerable to path traversal, allowing u | Sep 9, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-58762HIGH Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_image_proxy` | Sep 9, 2025 | 7.2 | 23 | NO | NO |
CVE-2026-31804MEDIUM Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forw | Mar 30, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-31799MEDIUM Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.17.0 for parameters "before" and "after" and from version 2.1 | Mar 30, 2026 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tautulli.
Media articles that mention a CVE ID that affects a product developed by Tautulli — matched by CVE ID, not by vendor name.