Skip to content
cyberHIGH2026-04-22 21:17 UTC

CVE-2026-41167 - Jellystat has SQL Injection that leads to to Remote Code Execution

CVE ID :CVE-2026-41167 Published : April 22, 2026, 9:17 p.m. | 23 minutes ago Description :Jellystat is a free and open source Statistics App for Jellyfin. Prior to version 1.1.10, multiple API endpoints in Jellystat build SQL queries by interpolating unsanitized request-body fields directly i

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber