cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 3 of 17
CVE-2026-86722P3HIGHCVSS 8.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86722 [HIGH] CWE-287 CVE-2026-86722: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vul AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty
nvd
CVE-2026-33352P3CRITICALCVSS 9.8fixed in 26.02026-03-23
CVE-2026-33352 [CRITICAL] CWE-89 CVE-2026-33352: WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injectio WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowCats` request parameter is sanitized only by stripping single-quote characters (`str_replace("'", '', ...)`), but this is trivially bypassed using a ba
ghsanvdosv
CVE-2026-33297P3CRITICALCVSS 9.1fixed in 26.02026-03-23
CVE-2026-33297 [CRITICAL] CWE-639 CVE-2026-33297: WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endp WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password containing non-numeric characters is silently coerced to the integer z
ghsanvdosv
CVE-2026-86190P3CRITICALCVSS 9.1≤ 29.02026-09-05
CVE-2026-86190 [CRITICAL] CWE-200 CVE-2026-86190: WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the disclosed session identifier to hijack viewer sessions, including admin
nvd
CVE-2025-34436P3HIGHCVSS 8.8fixed in 20.02025-12-17
CVE-2025-34436 [HIGH] CWE-639 CVE-2025-34436: AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belongin AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object reference. The upload functionality verifies authentication but does not enforce ownership checks.
nvd
CVE-2026-33037P3HIGHCVSS 8.1fixed in 26.02026-03-20
CVE-2026-33037 [HIGH] CWE-1188 CVE-2026-33037: WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deploy WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship with the admin password set to "password", which is automatically used to seed the admin account during installation, meaning any instance deployed without overriding SYSTEM_ADMIN_PASSWORD is immediatel
nvd
CVE-2026-86723P3HIGHCVSS 8.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86723 [HIGH] CWE-287 CVE-2026-86723: AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerabil AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authe
nvd
CVE-2026-33351P3CRITICALCVSS 9.1fixed in 26.02026-03-23
CVE-2026-33351 [CRITICAL] CWE-918 CVE-2026-33351: WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery ( WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended configuration for this file), the `$_REQUEST['webSiteRootURL']` parameter is used directly to cons
ghsanvdosv
CVE-2026-33651P3HIGHCVSS 8.8≤ 26.02026-03-23
CVE-2026-33651 [HIGH] CWE-89 CVE-2026-33651: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.js WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint passes `$_REQUEST['live_schedule_id']` through multiple functions without sanitization until it reaches `Scheduler_commands::getAllActiveOrToRepeat()`, which directly concatenates it into a SQL `LIKE` clause. Although intermediate functi
ghsanvdosv
CVE-2026-84187P3HIGHCVSS 8.2≤ 29.02026-09-01
CVE-2026-84187 [HIGH] CWE-284 CVE-2026-84187: AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows una AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled broadcast status fields by supplying fabri
nvd
CVE-2026-92914P3HIGHCVSS 8.1≤ 29.02026-09-17
CVE-2026-92914 [HIGH] CWE-287 CVE-2026-92914: AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verific AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass the second factor by sending a parameter-less GET request to verifyChallenge.json.php, which evaluates
nvd
CVE-2023-25313P3CRITICALCVSS 9.8fixed in 12.42023-04-25
CVE-2023-25313 [CRITICAL] CWE-78 CVE-2023-25313: OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attack OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
ghsanvdosv
CVE-2026-33479P3HIGHCVSS 8.8≤ 26.02026-03-23
CVE-2026-33479 [HIGH] CWE-94 CVE-2026-33479: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plug WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user input from `$_REQUEST['sections']` array values directly into PHP's `eval()` function. While the endpoint is gated behind `User::isAdmin()`, it has no CSRF token validation. Combined with AVideo's
ghsanvdosv
CVE-2026-33717P3HIGHCVSS 8.8≤ 26.02026-03-23
CVE-2026-33717 [HIGH] CWE-434 CVE-2026-33717: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVid WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a web-accessible temporary directory using the original URL's filename and extension (including `.php`). By providing an invalid `resolution` parameter, an attacke
ghsanvdosv
CVE-2025-48732P3CRITICALCVSS 9.8v14.4vdev master commit 8a8954ff2025-07-24
CVE-2025-48732 [CRITICAL] CWE-184 CVE-2025-48732: An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8 An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can request a .phar file to trigger this vulnerability.
nvd
CVE-2023-47862P3CRITICALCVSS 9.8v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-47862 [CRITICAL] CWE-73 CVE-2023-47862: A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVid A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.
nvd
CVE-2023-49715P3HIGHCVSS 8.8v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49715 [HIGH] CWE-434 CVE-2023-49715: A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functional A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send a series of HTTP requests to trigger this vulnerability.
nvd
CVE-2026-33649P3HIGHCVSS 8.8≤ 26.02026-03-23
CVE-2026-33649 [HIGH] CWE-352 CVE-2026-33649: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Perm WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets `session.cookie_samesite=None` on session
ghsanvdosv
CVE-2022-30690P3MEDIUMCVSS 6.1v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-30690 [MEDIUM] CWE-79 CVE-2022-30690: A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
nvd
CVE-2026-33502P3HIGHCVSS 8.2≤ 26.02026-03-23
CVE-2026-33502 [HIGH] CWE-918 CVE-2026-33502: WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticat WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to probe localhost/internal services and, when reachable, access internal HTTP
ghsanvdosv
Wwbn Avideo vulnerabilities | cvebase