CVE-2019-8939: Tautulli
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
data/interfaces/default/history.html in Tautulli 2.1.26 has XSS via a crafted Plex username that is mishandled when constructing the History page.
Affected products
- Tautulli Tautulli: version 2.1.26 only
Published 2019-02-19. Last modified 2026-06-17.