Home/Product/navidrome
Product

navidrome

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-25579
< 0.60.0
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash
6.5MEDIUM
CVE-2026-25578
< 0.60.0
Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulner
6.1MEDIUM
CVE-2025-48949
>= 0.55.0 and < 0.56.0
Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability du
9.8CRITICAL
CVE-2025-48948
< 0.56.0
Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.
6.5MEDIUM
CVE-2025-27112
>= 0.52.0 and < 0.54.5
Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5
6.5MEDIUM
CVE-2024-56362
< 0.54.1
Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the na
7.1HIGH
CVE-2024-47062
< 0.53.0
Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to
8.8HIGH
CVE-2024-41259
<= 0.52.3
Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account i
9.1CRITICAL
CVE-2024-32963
< 0.52.0
Navidrome is an open source web-based music collection server and streamer. In affected versions of Navidrome are subject to a par
4.2MEDIUM
CVE-2023-51442
< 0.50.2
Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidr
8.6HIGH
CVE-2022-23857
< 0.47.5
model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlis
6.5MEDIUM
threatengine.sh