Wwbn Avideo vulnerabilities
336 known vulnerabilities affecting wwbn/avideo.
Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1
Vulnerabilities
Page 16 of 17
CVE-2026-45580P4MEDIUMCVSS 5.4≤ 29.02026-05-29
CVE-2026-45580 [MEDIUM] CWE-79 CVE-2026-45580: WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scri
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, without htmlspecialchars(). A canStream user can persist a key containing " plus an event handler via plugi
ghsanvd
CVE-2026-100630P4MEDIUMCVSS 5.4fixed in 29.1.02026-09-26
CVE-2026-100630 [MEDIUM] CWE-79 CVE-2026-100630: AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 fiel
AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string,
nvd
CVE-2026-40928P4MEDIUMCVSS 5.4≤ 29.02026-04-21
CVE-2026-40928 [MEDIUM] CWE-352 CVE-2026-40928: WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpo
WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` accept state-changing requests via `$_REQUEST`/`$_GET` and persist changes tied to the caller's session user, without any anti-CSRF token, origin check, or referer check. A malicious page visited by a logged-in victim can silentl
nvd
CVE-2026-81733P4MEDIUMCVSS 5.1≤ 30.02026-08-28
CVE-2026-81733 [MEDIUM] CWE-352 CVE-2026-81733: WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vul
WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without enforcing a CSRF token or origin che
nvd
CVE-2026-90545P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90545 [MEDIUM] CWE-862 CVE-2026-90545: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access p
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests with a valid session to add comments to videos they cannot watch, by
nvd
CVE-2023-25314P4MEDIUMCVSS 6.1fixed in 12.42023-04-25
CVE-2023-25314 [MEDIUM] CWE-79 CVE-2023-25314: Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows
Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.
nvd
CVE-2026-89239P4MEDIUMCVSS 6.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89239 [MEDIUM] CWE-79 CVE-2026-89239: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding. Attackers can craft a Referer header containing */ to close the comment and inject arbitrary JavaScript that execu
nvd
CVE-2026-89244P4MEDIUMCVSS 6.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89244 [MEDIUM] CWE-79 CVE-2026-89244: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href attribute without HTML encoding, allowing attackers to inject malicious scripts that execute in visitors' browsers
nvd
CVE-2023-48730P4MEDIUMCVSS 5.4v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-48730 [MEDIUM] CWE-79 CVE-2023-48730: A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionali
A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2026-85577P4MEDIUMCVSS 5.4≤ c91b5975d2026-09-04
CVE-2026-85577 [MEDIUM] CWE-79 CVE-2026-85577: AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with . Attackers can craft a malicious URL with an error parameter containing script breakout sequences to execute arbitrary JavaScript in the victim's
nvd
CVE-2026-85159P4MEDIUMCVSS 5.4≤ c91b5975d2026-09-03
CVE-2026-85159 [MEDIUM] CWE-79 CVE-2026-85159: AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks protocol only, not HTML characters. Unauthenticated attackers can inject event handlers via relative URLs with embedded quotes to execute arbitrary JavaScr
nvd
CVE-2026-40929P4MEDIUMCVSS 5.4≤ 29.02026-04-21
CVE-2026-40929 [MEDIUM] CWE-352 CVE-2026-40929: WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.jso
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mutating JSON endpoint that deletes comments but performs no CSRF validation. It does not call `forbidIfIsUntrustedRequest()`, does not verify a CSRF/global token, and does not check `Origin`/`Referer`. Because AVideo intentionally s
nvd
CVE-2026-90546P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90546 [MEDIUM] CWE-862 CVE-2026-90546: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access p
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls
nvd
CVE-2026-88875P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88875 [MEDIUM] CWE-359 CVE-2026-88875: AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely s
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and API::get_api_video() calls removeSensitiveUserFields() only when the caller is neither authenticated nor using a va
nvd
CVE-2026-43882P4MEDIUMCVSS 4.3≤ 29.02026-05-11
CVE-2026-43882 [MEDIUM] CWE-93 CVE-2026-43882: WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthentica
WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler/downloadICS.php endpoint passes attacker-controlled title, description, and joinURL parameters into Scheduler::downloadICS(), which builds an ICS calendar file via the ICS helper class. ICS::escape_string() (objects/ICS.php:167-169
ghsanvd
CVE-2026-33294P4MEDIUMCVSS 4.3fixed in 26.02026-03-22
CVE-2026-33294 [MEDIUM] CWE-918 CVE-2026-33294: WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save end
WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other URL-fetching endpoints in AVideo that were hardened with `isSSRFSafeURL()`, this code path was missed.
ghsanvdosv
CVE-2026-47696P4MEDIUMCVSS 4.3≤ 29.02026-05-29
CVE-2026-47696 [MEDIUM] CWE-345 CVE-2026-47696: WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPaymen
WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST parameter. The endpoint contains a TODO for real Authorize.Net charging, hardcodes $paymentSuccess = true, and then calls YPTWallet::addBalance() without
ghsanvd
CVE-2026-89241P4MEDIUMCVSS 6.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89241 [MEDIUM] CWE-79 CVE-2026-89241: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute and inject event handlers that exec
nvd
CVE-2026-57944P4MEDIUMCVSS 5.4≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-08-22
CVE-2026-57944 [MEDIUM] CWE-352 CVE-2026-57944: AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGalle
AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying an administrator's session cookie to promote arbitrary channels to the
nvd
CVE-2026-34738P4MEDIUMCVSS 4.3≤ 26.02026-03-31
CVE-2026-34738 [MEDIUM] CWE-285 CVE-2026-34738: WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active" (a). This bypasses the admin-controlled moderation and draft workflows. The setStatus() method validates the st
ghsanvdosv