Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Tautulli

First CVE: Feb 19, 2019Active for: 7 yearsTotal CVEs: 11
50.9
VTI Score
TOP TARGET

Tautulli is a monitoring and analytics platform for Plex Media Server installations that sits at the intersection of web interface exposure and media-server privilege levels. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through web-application and file-handling weakness classes including cross-site scripting, cross-site request forgery, path traversal, code injection, and insecure file-name or path control that reflect the challenges of securing a third-party admin dashboard. Defenders should treat Tautulli instances, especially those reachable over the network, as requiring regular patching; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Tautulli over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2019
7 years ago
Most Recent CVE
Mar 30, 2026
116 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-19833MEDIUM
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous access can be achieved in applications that do not have a use
Dec 18, 20196.536NOYES
CVE-2026-28505CRITICAL
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed ev
Mar 30, 202610.032NONO
CVE-2026-32275CRITICAL
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-or
Mar 30, 20269.127NONO
CVE-2026-31831HIGH
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, a
Mar 30, 20267.526NONO
CVE-2025-58763HIGH
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. A command injection vulnerability in Tautulli v2.15.3 and prior allows attackers with administrative
Sep 9, 20257.224NONO
CVE-2025-58761HIGH
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 and prior is vulnerable to path traversal, al
Sep 9, 20257.524NONO
CVE-2025-58760HIGH
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.15.3 and earlier is vulnerable to path traversal, allowing u
Sep 9, 20257.524NONO
CVE-2025-58762HIGH
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_image_proxy`
Sep 9, 20257.223NONO
CVE-2026-31804MEDIUM
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy endpoint accepts a user-supplied img parameter and forw
Mar 30, 20265.320NONO
CVE-2026-31799MEDIUM
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.17.0 for parameters "before" and "after" and from version 2.1
Mar 30, 20264.919NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
36%
45%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (81.8%)
Unknown0 (0.0%)
Required2 (18.2%)
Privileges Required
Low0 (0.0%)
High3 (27.3%)
None8 (72.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
9.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Tautulli.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Tautulli — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Tautulli's Products

View all 2 CNAs →

Top CWEs