Does jellyfin have known vulnerabilities for bots to exploit? It's been up for several years with, afaik, no problems.
System has usual steps taken to harden it, JF is behind an apache proxy, letsencrypt handles ssl certs, fail2ban is running, and users are required to have strong passwords with no option to reset or self-register.
A VPN would not be practical for my situation, as the instance is used by various family members and friends. I'm happy for them to use my JF instance but I'm not providing VPN services as well.
If you're not referring to any specific vulnerabilities in JF then I feel confident there are no exceptional risks from allowing web access to JF? Just the usual ones?