CVE-2020-26948
CRITICAL EXPLOITED NUCLEIEmby SSRF HTTP Scanner
Title source: metasploitDescription
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
Exploits (2)
Nuclei Templates (1)
Emby < 4.5.0 - Server Server-Side Request Forgery
CRITICALby dwisiswant0
Shodan:
http.title:"emby"
FOFA:
title="emby"
Scores
CVSS v3
9.8
EPSS
0.9173
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-11-18
CWE
CWE-918
Status
published
Products (1)
emby/emby
< 4.5.0
Published
Oct 10, 2020
Tracked Since
Feb 18, 2026