Wwbn Avideo vulnerabilities
336 known vulnerabilities affecting wwbn/avideo.
Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1
Vulnerabilities
Page 15 of 17
CVE-2026-89240P4MEDIUMCVSS 6.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89240 [MEDIUM] CWE-79 CVE-2026-89240: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $securityFilter) directly into an attribute without URL- or HTML-encoding. A remote attacker can craft a
nvd
CVE-2026-33499P4MEDIUMCVSS 6.1≤ 26.02026-03-23
CVE-2026-33499 [MEDIUM] CWE-79 CVE-2026-33499: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbid
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` parameter directly into an HTML `` tag's attributes without any output encoding or sanitization. An attacker can craft a URL that breaks out of the `value` attr
ghsanvdosv
CVE-2023-30860P4MEDIUMCVSS 5.4fixed in 12.42023-05-08
CVE-2023-30860 [MEDIUM] CWE-79 CVE-2023-30860: WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can mak
WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters when creating a Meeting Room. This allows attacker to insert malicious scripts. Since any USER including the ADMIN c
ghsanvdosv
CVE-2026-41063P4MEDIUMCVSS 5.4≤ 29.02026-04-21
CVE-2026-41063 [MEDIUM] CVE-2026-41063: WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in A
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URLs in markdown link syntax to bypass sanitization. Commit cae8f0dadbdd962c89b91d0095c76edb8aadcacf
nvd
CVE-2026-92579P4MEDIUMCVSS 5.4≤ 29.02026-09-16
CVE-2026-92579 [MEDIUM] CWE-289 CVE-2026-92579: In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basen
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out authenticated users on cross-site POST re
nvd
CVE-2026-33500P4MEDIUMCVSS 5.4≤ 26.02026-03-23
CVE-2026-33500 [MEDIUM] CWE-79 CVE-2026-33500: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `` and `` tags in comments, but explicitly disables Parsedown's `safeMode`. This creates a bypass: markdown link syntax `[text](javascript:alert
ghsanvdosv
CVE-2026-41061P4MEDIUMCVSS 5.4≤ 29.02026-04-21
CVE-2026-41061 [MEDIUM] CWE-79 CVE-2026-41061: WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` re
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor, allowing arbitrary HTML/JavaScript to be appended after a valid duration prefix. The crafted duration is stored in the database and rendered without HTM
nvd
CVE-2026-33683P4MEDIUMCVSS 5.4≤ 26.02026-03-23
CVE-2026-33683 [MEDIUM] CWE-79 CVE-2026-33683: WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization o
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "about" field allows any registered user to inject arbitrary JavaScript that executes when other users visit their channel page. The `xss_esc()` function entity-encodes input before `strip_specific_tags()` ca
ghsanvdosv
CVE-2026-47694P4MEDIUMCVSS 5.4≤ 29.02026-05-29
CVE-2026-47694 [MEDIUM] CWE-79 CVE-2026-47694: WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptio
WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScript in a category description, which executes when another user views the affected Gallery/category pag
ghsanvd
CVE-2026-33238P4MEDIUMCVSS 4.3fixed in 26.02026-03-21
CVE-2026-33238 [MEDIUM] CWE-22 CVE-2026-33238: WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoi
WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob()` without restricting the path to an allowed base directory. An authenticated uploader can traverse the entire server filesystem by supplying arbitrary absolute paths, enumerating `.mp
ghsanvdosv
CVE-2026-90552P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90552 [MEDIUM] CWE-639 CVE-2026-90552: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist owner
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no authentication can retrieve sche
nvd
CVE-2026-90544P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90544 [MEDIUM] CWE-862 CVE-2026-90544: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access p
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary video IDs.
nvd
CVE-2025-50128P4MEDIUMCVSS 6.1v14.4vdev master commit 8a8954ff2025-07-24
CVE-2025-50128 [MEDIUM] CWE-79 CVE-2025-50128: A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functio
A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2025-46410P4MEDIUMCVSS 6.1v14.4vdev master commit 8a8954ff2025-07-24
CVE-2025-46410 [MEDIUM] CWE-79 CVE-2025-46410: A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId param
A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2025-53084P4MEDIUMCVSS 6.1v14.4vdev master commit 8a8954ff2025-07-24
CVE-2025-53084 [MEDIUM] CWE-79 CVE-2025-53084: A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of
A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2026-56347P4MEDIUMCVSS 6.1≤ 26.02026-06-20
CVE-2026-56347 [MEDIUM] CWE-79 CVE-2026-56347: AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in m
AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped menu item fields that execute for all site visitors, potentially stealing session cookies or performin
nvd
CVE-2026-33296P4MEDIUMCVSS 6.1fixed in 26.02026-03-22
CVE-2026-33296 [MEDIUM] CWE-601 CVE-2026-33296: WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open re
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.location` assignment without JavaScript-safe encoding. After a user completes the login popup flow, a timer callback e
ghsanvdosv
CVE-2025-34440P4MEDIUMCVSS 6.1fixed in 20.02025-12-17
CVE-2025-34440 [MEDIUM] CWE-601 CVE-2025-34440: AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validati
AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users to external sites, facilitating phishing attacks.
nvd
CVE-2023-47861P4MEDIUMCVSS 5.4v11.6v15fed957fb+1 more2024-01-10
CVE-2023-47861 [MEDIUM] CWE-79 CVE-2023-47861: A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of
A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2026-33295P4MEDIUMCVSS 5.4fixed in 26.02026-03-22
CVE-2026-33295 [MEDIUM] CWE-79 CVE-2026-33295: WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored c
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly into a JavaScript string literal without any escaping, allowing an attacker who can create or modify a
ghsanvdosv