CVE-2025-64325
Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious user can send an authentication request with a manipulated X-Emby-Client value, which gets added to the devices section of the admin dashboard without sanitization. This issue has been patched in version 4.8.1.0 and Beta version 4.9.0.0-beta.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.42%
- CWE
- CWE-79, CWE-116
- Published
- 2025-11-18
- Last modified
- 2026-03-12
Affected products
- EmbySupport Emby.Security
- EmbySupport Emby.Security
Weakness type
Related vulnerabilities
- CVE-2026-88055 — AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator
- CVE-2026-84819 — WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-84816 — WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-81795 — WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-81791 — WordPress EventON plugin <= 2.5.7 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-81782 — WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability
- CVE-2026-12682 — Stored XSS in Ankaref's LIBRID/LIBREF
- CVE-2026-88921 — MISP: Unescaped HTML Injection in PDF Report Element Rendering