Products: 1
Vulnerabilities: 11
Known Exploited: 0
2
Critical Level Threats
3
High Level Threats
6
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-25578
Navidrome is vulnerable to XSS via comment from song metadata
Last Modified: Apr 18, 2026
Published: Feb 04, 2026
CVE-2026-25579
Navidrome affected by Denial of Service and disk exhaustion via oversized `size` parameter in `/rest/getCoverArt` and `/share/img/<token>` endpoints
Last Modified: Apr 17, 2026
Published: Feb 04, 2026
CVE-2025-48949
Navidrome allows SQL Injection via role parameter
Last Modified: Aug 26, 2025
Published: May 30, 2025
CVE-2025-48948
Navidrome Transcoding Permission Bypass Vulnerability Report
Last Modified: Aug 26, 2025
Published: May 30, 2025
CVE-2025-27112
Navidrome has authentication bypass in Subsonic API with non-existent username
Last Modified: Feb 27, 2025
Published: Feb 24, 2025
Items Per Page
