Wwbn Avideo vulnerabilities
336 known vulnerabilities affecting wwbn/avideo.
Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1
Vulnerabilities
Page 14 of 17
CVE-2026-86724P4MEDIUMCVSS 6.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86724 [MEDIUM] CWE-352 CVE-2026-86724: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session cookies without token validation. Attackers can craft a malicious webpage that, when loaded by an administrator,
nvd
CVE-2026-50182P4MEDIUMCVSS 6.1≤ 29.02026-07-15
CVE-2026-50182 [MEDIUM] CWE-79 CVE-2026-50182: WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Refl
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenated directly into the href attribute of two pagination links in plugin/YouTubeAPI/gallerySection.php (lines 67 and 74) with no htmlspe
ghsanvd
CVE-2026-34396P4MEDIUMCVSS 6.1≤ 26.02026-03-31
CVE-2026-34396 [MEDIUM] CWE-79 CVE-2026-34396: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel ren
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms without applying htmlspecialchars() or any other output encoding. The jsonToFormElements() function in admin/functions.php directly interpolates user-controlled values into textarea contents, option elemen
ghsanvdosv
CVE-2026-43877P4MEDIUMCVSS 5.4≤ 29.02026-05-11
CVE-2026-43877 [MEDIUM] CWE-352 CVE-2026-43877: WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSave
WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legacy profile-photo endpoint that accepts a base64 POST parameter and writes the decoded bytes to videos/userPhoto/photo.png. Its only access control is User::isLogged(). It does not end in .json.php, so it is excluded from the project
ghsanvd
CVE-2026-41055P4MEDIUMCVSS 5.3≤ 29.02026-04-21
CVE-2026-41055 [MEDIUM] CVE-2026-41055: WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the actual HTTP request redirects traffic to internal endpoints. Commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 contain
nvd
CVE-2026-45620P4MEDIUMCVSS 5.3≤ 29.02026-05-29
CVE-2026-45620 [MEDIUM] CVE-2026-45620: WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no U
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenticated user enumeration.
ghsanvd
CVE-2026-91967P4MEDIUMCVSS 5.0≤ 29.02026-09-15
CVE-2026-91967 [MEDIUM] CWE-918 CVE-2026-91967: AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderConte
AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store attacker-chosen URLs as video links, triggering vulnerable function execution on every video watch page r
nvd
CVE-2026-85162P4MEDIUMCVSS 6.5≤ c91b5975d2026-09-03
CVE-2026-85162 [MEDIUM] CWE-352 CVE-2026-85162: AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/s
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authenticated streamers' RTMP keys, passwords, and titles, hijacking live broadcasts.
nvd
CVE-2026-33035P4MEDIUMCVSS 6.1fixed in 26.02026-03-20
CVE-2026-33035 [MEDIUM] CWE-79 CVE-2026-33035: WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS v
WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser. User input from a URL parameter flows through PHP's json_encode() into a JavaScript function that renders it via innerHTML, bypassing encoding and
ghsanvdosv
CVE-2026-34739P4MEDIUMCVSS 6.1≤ 26.02026-03-31
CVE-2026-34739 [MEDIUM] CWE-79 CVE-2026-34739: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other output encoding. This allows an attacker to inject arbitrary HTML and JavaScript via a crafted URL. Although the pag
ghsanvdosv
CVE-2025-34439P4MEDIUMCVSS 6.1fixed in 20.02025-12-17
CVE-2025-34439 [MEDIUM] CWE-601 CVE-2025-34439: AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of t
AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.
nvd
CVE-2023-50172P4MEDIUMCVSS 5.3v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-50172 [MEDIUM] CWE-640 CVE-2023-50172: A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation fu
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.
ghsanvdosv
CVE-2026-90542P4MEDIUMCVSS 5.4≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90542 [MEDIUM] CWE-639 CVE-2026-90542: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private live schedules they cannot view and learn the private schedule title from the generated email job.
nvd
CVE-2026-39367P4MEDIUMCVSS 5.4≤ 26.02026-04-07
CVE-2026-39367 [MEDIUM] CWE-79 CVE-2026-39367: WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic P
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a video's epg_link to a malicious XML file whose elements contain Jav
ghsanvdosv
CVE-2026-92584P4MEDIUMCVSS 6.1≤ 29.02026-09-16
CVE-2026-92584 [MEDIUM] CWE-79 CVE-2026-92584: AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerabilit
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings verbatim) directly into the `app` col
nvd
CVE-2026-58001P4MEDIUMCVSS 5.7≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-08-22
CVE-2026-58001 [MEDIUM] CWE-352 CVE-2026-58001: WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/v
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfers video ownership to an attacker-controlled account when an administrator views the video page.
nvd
CVE-2026-89246P4MEDIUMCVSS 5.4≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89246 [MEDIUM] CWE-1236 CVE-2026-89246: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated users can inject formulas starting with =, +, -, or @ characters that execute when administrators or video owner
nvd
CVE-2026-89148P4MEDIUMCVSS 5.4≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89148 [MEDIUM] CWE-352 CVE-2026-89148: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does not run, and when the request includes the sort parameter the script issues a Location header set to t
nvd
CVE-2026-86719P4MEDIUMCVSS 5.4≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86719 [MEDIUM] CWE-352 CVE-2026-86719: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site r
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST and invokes User::swapUser() without calling forbidIfNotPost() or forbidIfInvalidToken(), and the glob
nvd
CVE-2026-92586P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-16
CVE-2026-92586 [MEDIUM] CWE-862 CVE-2026-92586: AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access p
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests to the comment API endpoint with arbitrary video IDs to write comments on v
nvd