VendorsLee Peukermovaryany version
Vulnerabilities

Lee Peuker Movary any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-23839
Movary vulnerable to Cross-site Scripting with `?categoryUpdated=` param
Published 2026-01-19 · Analyzed
9.3EPSS 0.003
CVE-2026-23840
Movary vulnerable to Cross-site Scripting with `?categoryDeleted=` param
Published 2026-01-19 · Analyzed
9.3EPSS 0.003
CVE-2026-23841
Movary vulnerable to Cross-site Scripting with `?categoryCreated=` param
Published 2026-01-19 · Analyzed
9.3EPSS 0.003
CVE-2026-40349
Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{userId} by Setting isAdmin=true
Published 2026-04-18 · Analyzed
8.8EPSS 0.006
CVE-2026-40350
Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users to Enumerate All Users and Create Administrator Accounts
Published 2026-04-18 · Analyzed
8.8EPSS 0.006
CVE-2026-40348
Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Probing
Published 2026-04-18 · Analyzed
7.7EPSS 0.005
CVE-2025-64115
Movary unvalidated Referer header allows open redirect and phishing
Published 2025-10-30 · Analyzed
6.1EPSS 0.002
CVE-2025-64116
Movary vulnerable to an open redirect
Published 2025-10-30 · Analyzed
6.1EPSS 0.002