CVE Database
/

CVE-2026-32275

Back to search

CVE-2026-32275

Published: Mar 30, 2026

Modified: Apr 1, 2026

PUBLISHED

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-origin script injection and API key theft. This issue has been patched in version 2.17.0.

VendorProductVersions

Tautulli

Tautulli

affected
>= 1.3.10, < 2.17.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now