cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 13 of 17
CVE-2026-58003P4HIGHCVSS 7.1≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-08-22
CVE-2026-58003 [HIGH] CWE-352 CVE-2026-58003: WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the relea WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any embargoed video by manipulating the videos
nvd
CVE-2026-34362P4MEDIUMCVSS 5.4≤ 26.02026-03-27
CVE-2026-34362 [MEDIUM] CWE-613 CVE-2026-34362: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyToken WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or legitimately obtained tokens to pro
ghsanvdosv
CVE-2026-43879P4MEDIUMCVSS 5.4≤ 29.02026-05-11
CVE-2026-43879 [MEDIUM] CWE-918 CVE-2026-43879: WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated WWBN AVideo is an open source video platform. In versions up to and including 29.0, an authenticated user can configure their own donation-notification webhook URL to point at internal/loopback/metadata hosts (e.g. http://127.0.0.1:8080/..., http://169.254.169.254/latest/..., RFC1918 addresses). When any other user (including a second account owned
ghsanvd
CVE-2026-35452P4MEDIUMCVSS 5.3≤ 26.02026-04-06
CVE-2026-35452 [MEDIUM] CWE-200 CVE-2026-35452: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/clien WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces User::isAdmin(). The log contains internal filesystem paths, remote server URLs, and SSH connection meta
ghsanvdosv
CVE-2026-56380P4MEDIUMCVSS 5.3≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-08-22
CVE-2026-56380 [MEDIUM] CWE-200 CVE-2026-56380: AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by iterating through public channel names and extract them from the itunes:em
nvd
CVE-2026-34364P4MEDIUMCVSS 5.3≤ 26.02026-03-27
CVE-2026-34364 [MEDIUM] CWE-863 CVE-2026-34364: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories. WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access controls on categories. In the default request path (no `?user=` parameter), user group filtering is entirely skipped, exposing all non-private categor
ghsanvdosv
CVE-2026-34368P4MEDIUMCVSS 5.3≤ 26.02026-03-27
CVE-2026-34368 [MEDIUM] CWE-362 CVE-2026-34368: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBal WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sender's wallet balance, checks sufficiency in PHP, then writes the new balance — all without database transactions o
ghsanvdosv
CVE-2026-45731P4MEDIUMCVSS 4.9≤ 29.02026-05-29
CVE-2026-45731 [MEDIUM] CWE-22 CVE-2026-45731: WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['upd WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticated administrator can abuse this to read arbitrary text files reachable from the web-server process.
ghsanvd
CVE-2026-45610P4MEDIUMCVSS 6.5≤ 29.02026-05-29
CVE-2026-45610 [MEDIUM] CWE-306 CVE-2026-45610: WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request for WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getId(), false) on the session-authenticated user, and returns. There is no forbidIfIsUntrustedRequest()
ghsanvd
CVE-2026-84477P4MEDIUMCVSS 5.4≤ 29.02026-09-01
CVE-2026-84477 [MEDIUM] CWE-79 CVE-2026-84477: AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowin AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication.
nvd
CVE-2026-33759P4MEDIUMCVSS 5.3≤ 26.02026-03-27
CVE-2026-33759 [MEDIUM] CWE-639 CVE-2026-33759: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pla WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any authentication or authorization check. Private playlists (including `watch_later` and `favorite` types) are correctly hidden from listing endpoints via `
ghsanvdosv
CVE-2026-40908P4MEDIUMCVSS 5.3≤ 29.02026-04-21
CVE-2026-40908 [MEDIUM] CWE-200 CVE-2026-40908: WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enabling version fingerprinting against known CVEs), developer names and email addresses (PII), and commi
nvd
CVE-2026-85156P4MEDIUMCVSS 5.3≤ 29.02026-09-03
CVE-2026-85156 [MEDIUM] CWE-200 CVE-2026-85156: WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthen WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be hidden, including full URLs to unl
nvd
CVE-2026-85157P4MEDIUMCVSS 5.3≤ 29.02026-09-03
CVE-2026-85157 [MEDIUM] CWE-200 CVE-2026-85157: WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php end WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any visible playlist id, including
nvd
CVE-2026-35449P4MEDIUMCVSS 5.3≤ 26.02026-04-06
CVE-2026-35449 [MEDIUM] CWE-200 CVE-2026-35449: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagn WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addresses, session IDs, and user agents to unauthentica
ghsanvdosv
CVE-2026-43881P4MEDIUMCVSS 5.3≤ 29.02026-05-11
CVE-2026-43881 [MEDIUM] CWE-306 CVE-2026-43881: WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.js WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two unauthenticated paths that disclose the full set of registered user accounts. The isCompany request parameter causes the handler to set $ignoreAdmin = true for any non-admin caller (including unauthenticated visitors), which defeats
ghsanvd
CVE-2026-40935P4MEDIUMCVSS 5.3≤ 29.02026-04-21
CVE-2026-40935 [MEDIUM] CWE-804 CVE-2026-40935: WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` a WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from the query string with no clamping or sanitization, letting any unauthenticated client force the server to generate a 1-character CAPTCHA word. Combined with a case-insensitive `strcasecmp` comparison over
nvd
CVE-2026-33690P4MEDIUMCVSS 5.3≤ 26.0v<=26.02026-03-23
CVE-2026-33690 [MEDIUM] CWE-348 CVE-2026-33690: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAd WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client's IP address. An attacker can spoof their IP address by sending forged headers, bypassing any IP-based access controls or audit logging. Commit 1a1df
ghsanvdosv
CVE-2022-32769P4MEDIUMCVSS 5.0v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32769 [MEDIUM] CWE-862 CVE-2022-32769: Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWB Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability ex
nvd
CVE-2026-89245P4MEDIUMCVSS 6.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89245 [MEDIUM] CWE-352 CVE-2026-89245: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can craft a malicious form that submits a POST request to playlistRemove.php, causing a victim's playlist to be deleted w
nvd
Wwbn Avideo vulnerabilities | cvebase