Deluan
5 exploits
Active since Jan 2022
navidrome < 0.54.1 - Cleartext Storage of JWT Secret in Database
CVSS 7.1
Navidrome < 0.47.5 - Authenticated SQL Injection via Smart Playlist Processing
CVSS 6.5
navidrome < 0.50.2 - Unauthenticated Authentication Bypass via JWT Query Parameter
CVSS 8.6
navidrome < 0.54.1 - Cleartext Storage of JWT Secret in Database
CVSS 7.1
Navidrome <=0.54.5 - Authentication Bypass in Subsonic API
CVSS 6.5