CVE-2024-52053: Wowza Streaming Engine

Critical severity, CVSS 9.6. EPSS: 0.7% chance of exploitation in the next 30 days.

Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts.

Affected products

  • Wowza Streaming Engine: from 4.3.0, before 4.9.1 (fixed in 4.9.1)

Published 2024-11-21. Last modified 2026-06-17.