cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 2 of 17
CVE-2026-33648P2HIGHCVSS 8.8≤ 26.02026-03-23
CVE-2026-33648 [HIGH] CWE-78 CVE-2026-33648: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer e WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-controlled `users_id` and `liveTransmitionHistory_id` values from the JSON request body without any sanitization. This log file path is then concatenated directly into shell commands passed to `exec()`
ghsanvdosv
CVE-2023-30854P2HIGHCVSS 8.8fixed in 12.4≤ 12.42023-04-28
CVE-2023-30854 [HIGH] CWE-78 CVE-2023-30854: AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerabilit AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fixed in version 12.4.
ghsanvdosv
CVE-2026-33716P2CRITICALCVSS 9.4≤ 26.02026-03-23
CVE-2026-33716 [CRITICAL] CWE-287 CVE-2026-33716: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone l WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token verification requests. An attacker can redirect token verification to a server
ghsanvdosv
CVE-2026-33647P2HIGHCVSS 8.8≤ 26.02026-03-23
CVE-2026-33647 [HIGH] CWE-434 CVE-2026-33647: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGaller WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using `finfo` MIME type detection but derives the saved filename extension from the user-supplied original filename without an allowlist check. An attacker can upload a polyglot file (valid JPEG magi
ghsanvdosv
CVE-2026-85154P2CRITICALCVSS 9.8≤ 29.02026-09-03
CVE-2026-85154 [CRITICAL] CWE-269 CVE-2026-85154: WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner with full privileges, and the cr
nvd
CVE-2022-32770P3MEDIUMCVSS 6.1PoCv11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32770 [MEDIUM] CWE-79 CVE-2022-32770: A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the
nvd
CVE-2020-37172P2CRITICALCVSS 9.8v8.12026-02-11
CVE-2020-37172 [CRITICAL] CWE-640 CVE-2020-37172: AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to res AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
nvd
CVE-2026-29093P2CRITICALCVSS 9.8fixed in 24.02026-03-06
CVE-2026-29093 [CRITICAL] CWE-287 CVE-2026-29093: WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sessions in that memcached instance. An attacker who can reach port 11211 can read, modify, or flush se
ghsanvdosv
CVE-2026-84480P2CRITICALCVSS 9.8≤ 29.02026-09-01
CVE-2026-84480 [CRITICAL] CWE-613 CVE-2026-84480: WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, al WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
nvd
CVE-2022-32771P3MEDIUMCVSS 6.1PoCv11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32771 [MEDIUM] CWE-79 CVE-2022-32771: A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the
nvd
CVE-2022-32772P3MEDIUMCVSS 6.1PoCv11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32772 [MEDIUM] CWE-79 CVE-2022-32772: A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the
nvd
CVE-2026-84479P2CRITICALCVSS 9.1≤ 29.02026-09-01
CVE-2026-84479 [CRITICAL] CWE-290 CVE-2026-84479: WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely o WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credenti
nvd
CVE-2026-63304P2HIGHCVSS 8.1≤ 29.02026-07-16
CVE-2026-63304 [HIGH] CWE-78 CVE-2026-63304: AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/function AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can craft a valid encrypted codeToExec payload can break out of the single-quoted grep context and execute arb
nvd
CVE-2026-45578P2HIGHCVSS 8.8≤ 29.0fixed in 29.02026-05-29
CVE-2026-45578 [HIGH] CWE-78 CVE-2026-45578: WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metachar WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-quoting each argument but never calling escapeshellarg(). A ' in any of the three interpolated values ($us
ghsanvd
CVE-2025-34437P2HIGHCVSS 8.8fixed in 20.02025-12-17
CVE-2025-34437 [HIGH] CWE-639 CVE-2025-34437: AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to arbitrary video objects.
nvd
CVE-2026-33719P2HIGHCVSS 8.6≤ 26.02026-03-23
CVE-2026-33719 [HIGH] CWE-306 CVE-2026-33719: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin e WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disable.json.php` use key-based authentication with an empty string default key. When the CDN plugin is enabled but the key has not been configured (the default state), the key validation check is co
ghsanvdosv
CVE-2026-33770P3CRITICALCVSS 9.8≤ 26.02026-03-27
CVE-2026-33770 [CRITICAL] CWE-89 CVE-2026-33770: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTit WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` constructs a SQL SELECT query by directly interpolating both `$clean_title` and `$id` into the query string without using prepared statements or parameterized queries. An attacker who can trigger category
ghsanvdosv
CVE-2026-34374P3CRITICALCVSS 9.1≤ 26.02026-03-27
CVE-2026-34374 [CRITICAL] CWE-89 CVE-2026-34374: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedu WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is called as a fallback from `LiveTransmition::keyExists()` when the initial parameterized lookup return
nvd
CVE-2026-63305P3HIGHCVSS 8.1≤ 29.02026-07-16
CVE-2026-63305 [HIGH] CWE-78 CVE-2026-63305: AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint w AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell metacharacters into these fields to execute OS commands as the web-server user.
nvd
CVE-2026-33767P3HIGHCVSS 8.8≤ 26.02026-03-27
CVE-2026-33767 [HIGH] CWE-89 CVE-2026-33767: WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using a prepared statement placeholder (`?`) for `users_id` but directly concatenates `$this->videos_id` into the query string without parameterization. An attacker who can control the `videos_id` valu
ghsanvdosv
Wwbn Avideo vulnerabilities | cvebase