CVE-2026-96654 | Plex Media Server up to 1.42.1 Search searchOne cross site scripting

SecurityVulns

A vulnerability was found in Plex Media Server 0.9.9.2/0.9.9.2.374/0.9.9.3/0.9.9.10/1.42.1. It has been classified as problematic. This affects an unknown function of the component Search. The manipulation of the argument searchOne leads to cross site scripting.

This vulnerability is listed as CVE-2026-96654. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More