cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 12 of 17
CVE-2026-86718P4HIGHCVSS 7.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86718 [HIGH] CWE-352 CVE-2026-86718: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browse
nvd
CVE-2026-92582P4HIGHCVSS 7.1≤ 29.02026-09-16
CVE-2026-92582 [HIGH] CWE-352 CVE-2026-92582: AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. ob AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present in the request; the values are ne
nvd
CVE-2026-88870P4HIGHCVSS 7.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88870 [HIGH] CWE-352 CVE-2026-88870: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages with image tags pointing to savePublicKey.json.php to replace a logged-in victim's PGP 2FA public key, causing lockout
nvd
CVE-2026-89247P4MEDIUMCVSS 6.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89247 [MEDIUM] CWE-91 CVE-2026-89247: WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emits Content-Type: application/xml and writes the timeOffset and idTag values returned by AD_Server::getVMAPSFromRe
nvd
CVE-2026-27568P4MEDIUMCVSS 6.1fixed in 21.0≤ 26.02026-02-24
CVE-2026-27568 [MEDIUM] CWE-79 CVE-2026-27568: WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Safe Mode enabled. Markdown links are not sufficiently sanitized, allowing `javascript:` URIs to be rendered as clickable links. An authenticated low-privilege attacker can post a malicious comment that inj
ghsanvdosv
CVE-2026-43878P4MEDIUMCVSS 6.1≤ 29.02026-05-11
CVE-2026-43878 [MEDIUM] CWE-79 CVE-2026-43878: WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/Meet/ifra WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/Meet/iframe.php echoes the attacker-controlled user and pass query parameters unescaped into a JavaScript double-quoted string literal inside a block. An attacker who sends a victim to a crafted URL can break out of the string and execute arbitrary JavaScript i
ghsanvd
CVE-2026-86187P4MEDIUMCVSS 5.9≤ 29.02026-09-05
CVE-2026-86187 [MEDIUM] CWE-330 CVE-2026-86187: WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted MD5-based hashing.
nvd
CVE-2026-33237P4MEDIUMCVSS 5.5fixed in 26.02026-03-21
CVE-2026-33237 [MEDIUM] CWE-918 CVE-2026-33237: WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by `isValidURL()` (URL format check). Unlike other AVideo endpoints that were recently patched for SSRF (GHSA-9x67-f
ghsanvdosv
CVE-2026-89257P4MEDIUMCVSS 5.4≤ 29.02026-09-11
CVE-2026-89257 [MEDIUM] CWE-639 CVE-2026-89257: AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/cat AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the attacker-supplied $_REQUEST['id'] to Category::deleteAssets(), which recursively removes {systemRootPath}videos/ca
nvd
CVE-2026-34247P4MEDIUMCVSS 5.4≤ 26.02026-03-27
CVE-2026-34247 [MEDIUM] CWE-862 CVE-2026-34247: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary `live_schedule_id`. The endpoint only checks `User::isLogged()` but never verifies that the authenticated u
ghsanvdosv
CVE-2026-33501P4MEDIUMCVSS 5.3≤ 26.02026-03-23
CVE-2026-33501 [MEDIUM] CWE-862 CVE-2026-33501: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `pl WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated users to retrieve the complete permission matrix mapping user groups to plugins. All sibling endpoints in the same
ghsanvdosv
CVE-2026-30885P4MEDIUMCVSS 5.3fixed in 25.02026-03-10
CVE-2026-30885 [MEDIUM] CWE-306 CVE-2026-30885: WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and retrieve playlist information including playlist names, video IDs, and playlist status for any user
ghsanvdosv
CVE-2026-33763P4MEDIUMCVSS 5.3≤ 26.02026-03-27
CVE-2026-33763 [MEDIUM] CWE-307 CVE-2026-33763: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_vid WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given password is correct for any password-protected video. The endpoint returns a boolean `passwordIsCorrect` field with no rate limiting, CAPTCHA, or authentica
ghsanvdosv
CVE-2026-33685P4MEDIUMCVSS 5.3≤ 26.02026-03-23
CVE-2026-33685 [MEDIUM] CWE-862 CVE-2026-33685: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_S WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no authentication or authorization checks, allowing any unauthenticated attacker to extract ad campaign analytics data including video titles, user channel names, user IDs, ad campaign names, and impression/cl
ghsanvdosv
CVE-2026-90547P4MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90547 [MEDIUM] CWE-862 CVE-2026-90547: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissio WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint with a video ID parameter to retrieve sensitive chapter metadata withou
nvd
CVE-2026-35450P4MEDIUMCVSS 5.3≤ 26.02026-04-06
CVE-2026-35450 [MEDIUM] CWE-306 CVE-2026-35450: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpe WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg management endpoints (kill.ffmpeg.json.php, list.ffmpeg.json.php, ffmpeg.php) require User::isAdmin().
ghsanvdosv
CVE-2026-34369P4MEDIUMCVSS 5.3≤ 26.02026-03-27
CVE-2026-34369 [MEDIUM] CWE-862 CVE-2026-34369: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_vid WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos without verifying the video password. While the normal web playback flow enforces password checks vi
ghsanvdosv
CVE-2026-33688P4MEDIUMCVSS 5.3≤ 26.02026-03-23
CVE-2026-33688 [MEDIUM] CWE-204 CVE-2026-33688: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password rec WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allows an unauthenticated attacker to enumerate valid usernames and determine whether accounts are active, inactive,
ghsanvdosv
CVE-2026-90538P4MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90538 [MEDIUM] CWE-200 CVE-2026-90538: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorite and Watch Later playlists belonging to other users due to improper ca
nvd
CVE-2026-90549P4MEDIUMCVSS 5.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90549 [MEDIUM] CWE-200 CVE-2026-90549: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize acce WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin, filename, and hashId by sending an u
nvd
Wwbn Avideo vulnerabilities | cvebase