CVE-2019-19456: Wowza Streaming Engine

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streaming Engine 4.8.0.

Affected products

  • Wowza Streaming Engine: from 4.0.0, up to and including 4.8.0

Published 2020-05-18. Last modified 2026-06-17.