cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 17 of 17
CVE-2026-92585P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-16
CVE-2026-92585 [MEDIUM] CWE-862 CVE-2026-92585: AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot watch by calling the set.json.ph
nvd
CVE-2022-27462P4MEDIUMCVSS 6.1≤ 11.62022-04-05
CVE-2022-27462 [MEDIUM] CWE-79 CVE-2022-27462: Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVi Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.
nvd
CVE-2024-34899P4MEDIUMCVSS 5.4≥ 10.4, ≤ 12.42024-05-14
CVE-2024-34899 [MEDIUM] CWE-79 CVE-2024-34899: WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS). WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
ghsanvdosv
CVE-2026-85158P4MEDIUMCVSS 5.4≤ c91b5975d2026-09-03
CVE-2026-85158 [MEDIUM] CWE-79 CVE-2026-85158: AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbe AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping. Attackers can close the comment with --> and inject arbitrary JavaScript that executes when victims visit the crafted embed URL.
nvd
CVE-2022-32768P4MEDIUMCVSS 4.2v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32768 [MEDIUM] CWE-862 CVE-2022-32768: Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWB Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability ex
nvd
CVE-2026-33764P4MEDIUMCVSS 4.3≤ 26.02026-03-27
CVE-2026-33764 [MEDIUM] CWE-639 CVE-2026-33764: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endpoint loads AI response objects using an attacker-controlled `$_REQUEST['id']` parameter without validating that the AI response belongs to the specified video. An authenticated user with AI permissions can reference any AI response
ghsanvdosv
CVE-2026-92581P4MEDIUMCVSS 4.3≤ 29.02026-09-16
CVE-2026-92581 [MEDIUM] CWE-20 CVE-2026-92581: In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption pe
nvd
CVE-2026-88871P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88871 [MEDIUM] CWE-352 CVE-2026-88871: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script reads users_id and ExtraSubscribers from $_REQUEST and calls User::setExtraSubscribers() without requiring a POST r
nvd
CVE-2022-27463P4MEDIUMCVSS 6.1≤ 11.62022-04-05
CVE-2022-27463 [MEDIUM] CWE-601 CVE-2022-27463: Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
ghsanvdosv
CVE-2026-50183P4MEDIUMCVSS 4.7≤ 29.02026-07-15
CVE-2026-50183 [MEDIUM] CWE-79 CVE-2026-50183: WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Sc WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data API into the homepage gallery markup with no HTML encoding. The title is set by the YouTube video uploader (anyone in the world) and
ghsanvd
CVE-2026-90540P4MEDIUMCVSS 4.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90540 [MEDIUM] CWE-862 CVE-2026-90540: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissi WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos they cannot watch to playlists they own by submitting the video ID and playlist ID parameters.
nvd
CVE-2026-35180P4MEDIUMCVSS 4.3≤ 26.02026-04-06
CVE-2026-35180 [MEDIUM] CWE-352 CVE-2026-35180: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization end WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-based security check executes. Combined with SameSite=None cookie policy, a cross-origin POST can overwr
nvd
CVE-2026-35181P4MEDIUMCVSS 4.3≤ 26.02026-04-06
CVE-2026-35181 [MEDIUM] CWE-352 CVE-2026-35181: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configurat WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based security check via ignoreTableSecurityCheck(), removing the only other layer of defense. Combined with Same
ghsanvdosv
CVE-2026-43883P4MEDIUMCVSS 4.2≤ 29.02026-05-11
CVE-2026-43883 [MEDIUM] CWE-639 CVE-2026-43883: WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.json.php cancels a PayPal billing agreement using an attacker-supplied agreement parameter without verifying that the authenticated user owns the agreement. A low-privilege authenticated user who learns or obtains another user's PayPa
ghsanvd
CVE-2026-85161P4MEDIUMCVSS 4.3≤ c91b5975d2026-09-03
CVE-2026-85161 [MEDIUM] CWE-352 CVE-2026-85161: AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster. AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster and thumbnail files via GET requests.
nvd
CVE-2026-35448P4LOWCVSS 3.7≤ 26.02026-04-06
CVE-2026-35448 [LOW] CWE-862 CVE-2026-35448: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an AJAX polling helper for the authenticated invoice.php page, but it performs no access control checks of its own. Si
ghsanvdosv
Wwbn Avideo vulnerabilities | cvebase