cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 10 of 17
CVE-2026-34395P3MEDIUMCVSS 6.5≤ 26.02026-03-31
CVE-2026-34395 [MEDIUM] CWE-862 CVE-2026-34395: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/ WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks User::isLogged() but does not check User::isAdmin(), so any registered user can dump the full user da
ghsanvdosv
CVE-2026-92583P3MEDIUMCVSS 6.5≤ 29.02026-09-16
CVE-2026-92583 [MEDIUM] CWE-307 CVE-2026-92583: AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomi AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minut
nvd
CVE-2026-34245P3MEDIUMCVSS 6.3≤ 26.02026-03-27
CVE-2026-34245 [MEDIUM] CWE-862 CVE-2026-34245: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Play WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast schedules targeting any playlist on the platform, regardless of ownership. When the schedule executes, the rebr
ghsanvdosv
CVE-2026-84483P3MEDIUMCVSS 5.3≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-09-01
CVE-2026-84483 [MEDIUM] CWE-321 CVE-2026-84483: WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge authentication tokens by computing hash_hmac with the site's base URL as the key and submit arbitrary passwords to
nvd
CVE-2026-86726P3MEDIUMCVSS 6.5≤ 29.02026-09-08
CVE-2026-86726 [MEDIUM] CWE-522 CVE-2026-86726: AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php tha AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across
nvd
CVE-2026-89252P3MEDIUMCVSS 6.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89252 [MEDIUM] CWE-639 CVE-2026-89252: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveL AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS source and metadata by supplying an existing linkId, redirecting viewers to attacker-controlled medi
nvd
CVE-2026-39366P3MEDIUMCVSS 6.5≤ 26.02026-04-07
CVE-2026-39366 [MEDIUM] CWE-345 CVE-2026-39366: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate their wallet balance and renew subscriptions. The newer ipnV2.php and webhook.php handlers correctly
ghsanvdosv
CVE-2026-89251P3MEDIUMCVSS 6.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89251 [MEDIUM] CWE-345 CVE-2026-89251: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in p AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video wit
nvd
CVE-2026-43876P3MEDIUMCVSS 6.4≤ 29.02026-05-11
CVE-2026-43876 [MEDIUM] CWE-79 CVE-2026-43876: WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySu WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php takes the raw message POST parameter and passes it into sendSiteEmail(), which substitutes it directly into an HTML email template (via str_replace on the {message} placeholder) and renders it with PHPMailer::msgHTML(). There is no H
ghsanvd
CVE-2026-91966P3MEDIUMCVSS 5.8≤ 29.02026-09-15
CVE-2026-91966 [MEDIUM] CWE-918 CVE-2026-91966: AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the che AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authenticat
nvd
CVE-2026-89243P3HIGHCVSS 8.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89243 [HIGH] CWE-79 CVE-2026-89243: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scr WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser when other administrators access the user
nvd
CVE-2026-33041P3MEDIUMCVSS 5.3fixed in 26.02026-03-20
CVE-2026-33041 [MEDIUM] CWE-200 CVE-2026-33041: WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json. WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing algorithm to any unauthenticated user. An attacker can submit arbitrary passwords and receive their hashed equivalents, enabling offline password cracking against leaked database hashes. If an attacker ob
ghsanvdosv
CVE-2026-35179P3MEDIUMCVSS 5.3≤ 26.02026-04-06
CVE-2026-35179 [MEDIUM] CWE-862 CVE-2026-35179: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher p WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts user-controlled parameters including an access token, container ID, and Instagram account ID, and passes
ghsanvdosv
CVE-2026-43875P3MEDIUMCVSS 6.8≤ 29.02026-05-11
CVE-2026-43875 [MEDIUM] CWE-598 CVE-2026-43875: WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileMan WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=&pass= where is the victim's stored password hash (md5(hash("whirlpool", sha1(password)))) read directly from the users table. AVideo's own login endpoint
ghsanvd
CVE-2026-33766P3MEDIUMCVSS 6.5≤ 26.02026-03-27
CVE-2026-33766 [MEDIUM] CWE-918 CVE-2026-33766: WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL() WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP ranges before fetching, but `url_get_contents()` follows HTTP redirects without re-validating the redirect target. An attacker can bypass SSRF protection by redirecting from a public URL to an internal targ
ghsanvdosv
CVE-2026-92912P3MEDIUMCVSS 6.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-17
CVE-2026-92912 [MEDIUM] CWE-330 CVE-2026-92912: AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers who know the channel creation time can brute-force the five-digit microsecond component to forge valid stream keys
nvd
CVE-2026-34716P3MEDIUMCVSS 6.4≤ 26.02026-03-31
CVE-2026-34716 [MEDIUM] CWE-79 CVE-2026-34716: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugi WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the heading parameter. The toast plugin constructs the heading as raw HTML ('' + heading + '') and inserts it into the D
ghsanvdosv
CVE-2026-90543P3MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90543 [MEDIUM] CWE-306 CVE-2026-90543: WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin ena WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg` parameters from $_REQUEST, resolves the stream owner via LiveTransmition::keyExists, and verifies that the strea
nvd
CVE-2026-89248P3MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89248 [MEDIUM] CWE-200 CVE-2026-89248: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authoriz AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON containing the absolute filesystem path of the WebRTC2RTMP helper binary (reve
nvd
CVE-2026-90551P3MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90551 [MEDIUM] CWE-862 CVE-2026-90551: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist owner WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-p
nvd
Wwbn Avideo vulnerabilities | cvebase