CVE-2019-8939: Tautulli

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.

Affected products

Published 2019-02-19. Last modified 2026-06-17.