CVE-2017-18375: Ampache

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.

Affected products

  • Ampache Ampache: version 3.8.3 only

Published 2019-05-24. Last modified 2026-06-17.