cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 11 of 17
CVE-2026-40926P3HIGHCVSS 7.1≤ 29.02026-04-21
CVE-2026-40926 [HIGH] CWE-352 CVE-2026-40926: WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endp WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check (`Category::canCreateCategory()` / `User::isAdmin()`) and perform state-changing actions against the d
nvd
CVE-2023-49862P3MEDIUMCVSS 6.5vdev master commit 15fed957fb2024-01-10
CVE-2023-49862 [MEDIUM] CWE-73 CVE-2023-49862: An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image uploa An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_gifimage` parameter.
nvd
CVE-2023-49863P3MEDIUMCVSS 6.5vdev master commit 15fed957fb2024-01-10
CVE-2023-49863 [MEDIUM] CWE-73 CVE-2023-49863: An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image uploa An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_webpimage` parameter.
nvd
CVE-2023-47171P3MEDIUMCVSS 6.5v11.6v15fed957fb+1 more2024-01-10
CVE-2023-47171 [MEDIUM] CWE-73 CVE-2023-47171: An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path function An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
nvd
CVE-2023-49864P3MEDIUMCVSS 6.5vdev_master_commit_15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49864 [MEDIUM] CWE-73 CVE-2023-49864: An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image uploa An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_image` parameter.
nvd
CVE-2026-34613P3MEDIUMCVSS 6.5≤ 26.02026-03-31
CVE-2026-34613 [MEDIUM] CWE-352 CVE-2026-34613: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint object WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session but does not validate a CSRF token. Additionally, the plugins database table is explicitly listed in ignoreTableSe
ghsanvdosv
CVE-2026-45619P3MEDIUMCVSS 6.5≤ 29.02026-05-29
CVE-2026-45619 [MEDIUM] CVE-2026-45619: WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveA WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS pinning via CURLOPT_RESOLVE, opening DNS-rebinding TOCTOU.
ghsanvd
CVE-2026-64626P3MEDIUMCVSS 6.4v0dbadbcaaa1b415c7db078a72dc4b26d9fac04852026-07-20
CVE-2026-64626 [MEDIUM] CWE-918 CVE-2026-64626: AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vul AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the r
nvd
CVE-2026-46337P3MEDIUMCVSS 5.3≤ 29.02026-05-29
CVE-2026-46337 [MEDIUM] CWE-22 CVE-2026-46337: WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacke WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that the PHP user can open — including private user-profile photos that the application's normal serving wrappers gate behind ACLs, admin-uploaded thumbnails, encrypted-video poster frames, and image co
ghsanvd
CVE-2026-90539P3MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90539 [MEDIUM] CWE-200 CVE-2026-90539: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authenticatio WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve hidden menu item URLs including embe
nvd
CVE-2026-90536P3MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90536 [MEDIUM] CWE-200 CVE-2026-90536: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without aut
nvd
CVE-2026-90541P3MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90541 [MEDIUM] CWE-200 CVE-2026-90541: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the endpoint to read inactive and admin-only menu names that are not displayed in the public navbar.
nvd
CVE-2026-88872P3HIGHCVSS 7.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88872 [HIGH] CWE-352 CVE-2026-88872: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET request. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, sets
nvd
CVE-2026-90548P3MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90548 [MEDIUM] CWE-200 CVE-2026-90548: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissio WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint, then fetch the exposed files with
nvd
CVE-2026-33684P3MEDIUMCVSS 5.3fixed in 29.02026-07-15
CVE-2026-33684 [MEDIUM] CWE-862 CVE-2026-33684: WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possibl WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts emailVerified, canUpload, canStr
ghsanvd
CVE-2026-88873P4HIGHCVSS 7.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88873 [HIGH] CWE-352 CVE-2026-88873: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrators' browsers to request
nvd
CVE-2026-34611P4MEDIUMCVSS 6.5≤ 26.02026-03-31
CVE-2026-34611 [MEDIUM] CWE-352 CVE-2026-34611: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint object WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session status, it does not validate a CSRF token. Because AVideo sets SameSite=None on session cookies, a c
ghsanvdosv
CVE-2026-33761P4MEDIUMCVSS 5.3≤ 26.02026-03-27
CVE-2026-33761 [MEDIUM] CWE-200 CVE-2026-33761: WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any authentication check, while every other endpoint in the same plugin directories (`add.json.php`, `delete.json.php`, `index.php`) requires `User::isAdmin()`. An unauthenticated attacker can retrieve all
ghsanvdosv
CVE-2026-90550P4MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90550 [MEDIUM] CWE-200 CVE-2026-90550: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorizatio WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint with a video ID parameter to retrieve password-protected video titles and owner email addresses without authenticat
nvd
CVE-2026-43880P4MEDIUMCVSS 5.3≤ 29.02026-05-11
CVE-2026-43880 [MEDIUM] CWE-940 CVE-2026-43880: WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmai WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes two branches depending on whether contactForm=1 is submitted. When the parameter is omitted, the endpoint sets $sendTo to an attacker-supplied email and, for unauthenticated callers, uses the site's own contact email as the message
ghsanvd
Wwbn Avideo vulnerabilities | cvebase