← Vulnerability feed

Vulnerability record · CVE-2014-9304 · published 7 December 2014

CVE-2014-9304: Plex media server permissions and access controls vulnerability

Plex · Media Server

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

7.5 CVSS 2.0 High EPSS 8.1% · top 5.4% CWE-264 · Permissions and access controls
7.5CVSS 2.0 base score
8.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9304 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.2CVE-2020-5741Plex Media Server Windows deserialization leads to Python code executionPlex Media Server on Windows deserializes untrusted data, allowing a remote, authenticated attacker to execute arbitrary Python code. The flaw is a C…KEVEPSS 73%analysed9.8CVE-2018-13415Plex media server xml external entity (xxe) vulnerabilityIn Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.…EPSS 32%8.8CVE-2020-5742Plex media server vulnerabilityImproper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.EPSS 1.4%8.8CVE-2019-19141Plex media server path traversal vulnerabilityThe Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account r…EPSS 4.7%7.8CVE-2020-5740Plex media server uncontrolled search path element vulnerabilityImproper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privi…EPSS 0.75%7.5CVE-2021-33959Plex media server origin validation error vulnerabilityPlex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.EPSS 15%7.1CVE-2025-69414Plex media server incorrect authorization vulnerabilityPlex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.EPSS 0.25%7.1CVE-2025-69415Plex media server vulnerabilityIn Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the devic…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2014-9304), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.