Wwbn Avideo vulnerabilities
336 known vulnerabilities affecting wwbn/avideo.
Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1
Vulnerabilities
Page 4 of 17
CVE-2022-33147P3HIGHCVSS 8.8v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-33147 [HIGH] CWE-89 CVE-2022-33147: A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev mast
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the aVideoEncoder functionality which can be used to add new videos, allowin
nvd
CVE-2022-33149P3HIGHCVSS 8.8v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-33149 [HIGH] CWE-89 CVE-2022-33149: A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev mast
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the CloneSite plugin, allowing an attacker to inject SQL by manipulating the
nvd
CVE-2022-32282P3HIGHCVSS 8.8v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32282 [HIGH] CWE-836 CVE-2022-32282: An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master comm
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased privileges.
nvd
CVE-2026-41064P3CRITICALCVSS 9.3≤ 29.02026-04-22
CVE-2026-41064 [CRITICAL] CVE-2026-41064: WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fi
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation regex `/^http/` accepts strings like `httpevil[.]com`. Commit 78bccae74634ead68aa6528d631c9ec4fd7aa536 cont
nvd
CVE-2026-33480P3HIGHCVSS 8.6≤ 26.02026-03-23
CVE-2026-33480 [HIGH] CWE-918 CVE-2026-33480: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeU
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`). The unauthenticated `plugin/LiveLinks/proxy.php` endpoint uses this function to validate URLs before fetching them with curl, but the IPv4-mapped IPv6 prefix p
ghsanvdosv
CVE-2026-33513P3HIGHCVSS 7.5≤ 26.02026-03-23
CVE-2026-33513 [HIGH] CWE-22 CVE-2026-33513: WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticat
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test this yielded confirmed file disclo
ghsanvdosv
CVE-2026-86728P3HIGHCVSS 7.5≤ 29.02026-09-08
CVE-2026-86728 [HIGH] CWE-306 CVE-2026-86728: AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without au
nvd
CVE-2026-89250P3HIGHCVSS 7.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89250 [HIGH] CWE-306 CVE-2026-89250: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed stream key to download recorded live video files without authentication or a
nvd
CVE-2023-49589P3HIGHCVSS 8.8v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49589 [HIGH] CWE-640 CVE-2023-49589: An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation funct
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2026-33507P3HIGHCVSS 8.8≤ 26.02026-03-23
CVE-2026-33507 [HIGH] CWE-352 CVE-2026-33507: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/plu
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting `session.cookie_samesite = 'None'` for HTTPS connectio
ghsanvdosv
CVE-2026-90537P3HIGHCVSS 8.2≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-12
CVE-2026-90537 [HIGH] CWE-862 CVE-2026-90537: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live titles and email addresses, and tr
nvd
CVE-2026-33038P3HIGHCVSS 8.1fixed in 26.02026-03-20
CVE-2026-33038 [HIGH] CWE-306 CVE-2026-33038: WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthentica
WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfiguration.php endpoint. install/checkConfiguration.php performs full application initialization: database setup, admin account creation, and configuration file write, all from an unauthenticated POST
ghsanvdosv
CVE-2026-27732P3HIGHCVSS 8.1fixed in 22.0≤ 26.02026-02-24
CVE-2026-27732 [HIGH] CWE-918 CVE-2026-27732: WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` AP
WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and fetches the referenced resource server-side without proper validation or an allow-list. This allows authenticated users to trigger server-side requests to arbitrary URLs (including internal network endpoi
ghsanvdosv
CVE-2026-86720P3HIGHCVSS 8.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86720 [HIGH] CWE-639 CVE-2026-86720: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of l
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_res
nvd
CVE-2026-88874P3HIGHCVSS 7.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88874 [HIGH] CWE-200 CVE-2026-88874: AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enfor
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected transmission's RTMP stream key, its isPasswordProtected flag, and its HLS (m3u8) URL to unauthenticated c
nvd
CVE-2026-84208P3HIGHCVSS 7.5≤ 29.02026-09-01
CVE-2026-84208 [HIGH] CWE-89 CVE-2026-84208: AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Loca
AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers to execute UNION-based SQL injecti
nvd
CVE-2022-33148P3HIGHCVSS 8.8v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-33148 [HIGH] CWE-89 CVE-2022-33148: A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev mast
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulatin
nvd
CVE-2026-33039P3HIGHCVSS 8.6fixed in 26.02026-03-20
CVE-2026-33039 [HIGH] CWE-918 CVE-2026-33039: WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy
WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal/private networks using isSSRFSafeURL(), but only checks the initial URL. When the initial URL responds with an HTTP redirect (Location header), the redirect target is fetched via fakeBrowser()
ghsanvdosv
CVE-2022-30605P3HIGHCVSS 8.8v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-30605 [HIGH] CWE-384 CVE-2022-30605: A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
nvd
CVE-2026-92578P3HIGHCVSS 8.1≤ 29.02026-09-16
CVE-2026-92578 [HIGH] CWE-287 CVE-2026-92578: WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password h
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to l
nvd