plex CVE Vulnerabilities & Metrics

Focus on plex vulnerabilities and metrics.

Last updated: 08 Mar 2026, 23:25 UTC

About plex Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with plex. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total plex CVEs: 12
Earliest CVE date: 02 Dec 2014, 16:59 UTC
Latest CVE date: 02 Jan 2026, 17:16 UTC

Latest CVE reference: CVE-2025-69417

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 4

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical plex CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.14

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 6
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS plex CVEs

These are the five CVEs with the highest CVSS scores for plex, sorted by severity first and recency.

All CVEs for plex

CVE-2025-69417 plex vulnerability CVSS: 0 02 Jan 2026, 17:16 UTC

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.

CVE-2025-69416 plex vulnerability CVSS: 0 02 Jan 2026, 17:16 UTC

In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.

CVE-2025-69415 plex vulnerability CVSS: 0 02 Jan 2026, 17:16 UTC

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.

CVE-2025-69414 plex vulnerability CVSS: 0 02 Jan 2026, 17:16 UTC

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

CVE-2021-33959 plex vulnerability CVSS: 0 18 Jan 2023, 14:15 UTC

Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

CVE-2021-42835 plex vulnerability CVSS: 6.9 08 Dec 2021, 15:15 UTC

An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).

CVE-2020-5742 plex vulnerability CVSS: 6.8 15 Jun 2020, 20:15 UTC

Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

CVE-2020-5741 plex vulnerability CVSS: 6.5 08 May 2020, 13:15 UTC

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

CVE-2020-5740 plex vulnerability CVSS: 7.2 22 Apr 2020, 16:15 UTC

Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.

CVE-2019-19141 plex vulnerability CVSS: 6.5 19 Dec 2019, 23:15 UTC

The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server has permissions. This allows remote code execution via a variety of methods, such as (on a default Ubuntu installation) creating a .ssh folder in the plex user's home directory via directory traversal, uploading an SSH authorized_keys file there, and logging into the host as the Plex user via SSH.

CVE-2018-21031 plex vulnerability CVSS: 4.0 18 Nov 2019, 17:15 UTC

Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was associated with Plex Media Server 1.18.2.2029-36236cc4c as the affected product and version. Further research indicated that Tautulli is the correct affected product.

CVE-2018-13415 plex vulnerability CVSS: 7.5 13 Aug 2018, 17:29 UTC

In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Plex, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

CVE-2014-9304 plex vulnerability CVSS: 7.5 07 Dec 2014, 21:59 UTC

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

CVE-2014-9181 plex vulnerability CVSS: 5.0 02 Dec 2014, 16:59 UTC

Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot dot) in the URI to resources/.