cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 5 of 17
CVE-2026-33293P3HIGHCVSS 8.1fixed in 26.0≤ 29.02026-03-22
CVE-2026-33293 [HIGH] CWE-22 CVE-2026-33293: WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in ` WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credentials can use path traversal sequences (e.g., `../../`) to delete arbitrary files on the server, including critical
ghsanvdosv
CVE-2026-85155P3HIGHCVSS 7.5≤ 29.02026-09-03
CVE-2026-85155 [HIGH] CWE-89 CVE-2026-85155: WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can exploit this ordering oracle to infer password hash values and recovery token
nvd
CVE-2026-33319P3HIGHCVSS 7.5fixed in 26.02026-03-22
CVE-2026-33319 [HIGH] CWE-78 CVE-2026-33319: WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` m WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, without sanitization via `escapeshellarg()`. If an attacker can influence the LinkedIn API response (via MI
ghsanvdosv
CVE-2026-86729P3HIGHCVSS 7.4≤ 29.02026-09-08
CVE-2026-86729 [HIGH] CWE-307 CVE-2026-86729: WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with no throttling for any client, allo
nvd
CVE-2026-84478P3HIGHCVSS 7.3≤ 29.02026-09-01
CVE-2026-84478 [HIGH] CWE-73 CVE-2026-84478: WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allo WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit this to destroy audit logs and probe for file existence on the server, with the vulnerability enabling bot
nvd
CVE-2022-34652P3HIGHCVSS 8.8v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-34652 [HIGH] CWE-89 CVE-2022-34652: A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev mast A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulatin
nvd
CVE-2026-41058P3HIGHCVSS 8.1≤ 29.02026-04-21
CVE-2026-41058 [HIGH] CVE-2026-41058: WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVi WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in the GET parameter. Commit 3c729717c26f160014a5c86b0b6accdbd613e7b2 contains an updated fix.
nvd
CVE-2026-41056P3HIGHCVSS 8.1≤ 29.02026-04-21
CVE-2026-41056 [HIGH] CWE-942 CVE-2026-41056: WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in `objects/functions.php` reflects any arbitrary `Origin` header back in `Access-Control-Allow-Origin` along with `Access-Control-Allow-Credentials: true`. This function is called by both `plugin/API/get.json.php` and `plugin/API/set.j
nvd
CVE-2026-33493P3HIGHCVSS 8.1≤ 26.02026-03-23
CVE-2026-33493 [HIGH] CWE-22 CVE-2026-33493: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/imp WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `objects/listFiles.json.php`, which was hardened with a `realpath()` + directory prefix check to restrict paths to the
ghsanvdosv
CVE-2026-33488P3HIGHCVSS 8.1≤ 26.02026-03-23
CVE-2026-33488 [HIGH] CWE-326 CVE-2026-33488: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys( WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who obtains a target user's public key can factor the 512-bit RSA modulus on commodity hardware in hours, der
ghsanvdosv
CVE-2026-33483P3HIGHCVSS 7.5≤ 26.02026-03-23
CVE-2026-33483 [HIGH] CWE-770 CVE-2026-33483: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncod WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An unauthenticated remote attacker can send arbitrary POST data which is written to persistent temp files in `/tmp/`
ghsanvdosv
CVE-2023-49599P3CRITICALCVSS 9.8v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49599 [CRITICAL] CWE-331 CVE-2023-49599: An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery
ghsanvdosv
CVE-2026-34731P3HIGHCVSS 7.5≤ 26.02026-03-31
CVE-2026-34731 [HIGH] CWE-306 CVE-2026-34731: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthenticated users to terminate any active live stream. The endpoint processes RTMP callback events to mark streams as finished in the database, but performs no authentication or authorization checks before doi
ghsanvdosv
CVE-2026-33292P3HIGHCVSS 7.5fixed in 26.02026-03-22
CVE-2026-33292 [HIGH] CWE-22 CVE-2026-33292: WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`vi WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The `videoDirectory` GET parameter is used in two divergent code paths — one for authorization (which trunc
ghsanvdosv
CVE-2026-33692P3HIGHCVSS 7.5fixed in 29.02026-07-16
CVE-2026-33692 [HIGH] CWE-20 CVE-2026-33692: WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenti WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache document root, causing the .env file — which contains database credentials, admin passwords, and infrast
ghsanvd
CVE-2026-92913P3HIGHCVSS 7.4≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-17
CVE-2026-92913 [HIGH] CWE-330 CVE-2026-92913: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo- AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely from uniqid() (sprintf('%08x%05x', seconds, microseconds)) with a single non-CSPRNG rand() character used
nvd
CVE-2026-54458P3CRITICALCVSS 9.6≤ 29.02026-07-15
CVE-2026-54458 [CRITICAL] CWE-79 CVE-2026-54458: WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin of every administrator currently viewing a page that renders the YPTSocket online-users debug panel. pl
nvd
CVE-2026-88869P3CRITICALCVSS 9.3≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88869 [CRITICAL] CWE-79 CVE-2026-88869: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad
nvd
CVE-2021-21286P3HIGHCVSS 8.8fixed in 10.22021-02-01
CVE-2021-21286 [HIGH] CWE-863 CVE-2021-21286: AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform before version 10.2 there is an authorization bypass vulnerability which enables an ordinary user to get admin control. This is fixed in version 10.2. All queries now remove the pass hash and the recoverPass hash.
nvd
CVE-2026-59256P3HIGHCVSS 7.5≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-08-22
CVE-2026-59256 [HIGH] CWE-200 CVE-2026-59256: WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to bypass authorization checks in other
nvd
Wwbn Avideo vulnerabilities | cvebase