Wwbn Avideo vulnerabilities
336 known vulnerabilities affecting wwbn/avideo.
Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1
Vulnerabilities
Page 6 of 17
CVE-2026-88876P3HIGHCVSS 7.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88876 [HIGH] CWE-200 CVE-2026-88876: AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vu
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the dire
nvd
CVE-2026-43873P3HIGHCVSS 7.5≤ 29.02026-05-11
CVE-2026-43873 [HIGH] CWE-209 CVE-2026-43873: WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($global['systemRootPath'] . $global['salt'])) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to
ghsanvd
CVE-2026-33650P3HIGHCVSS 7.6≤ 26.02026-03-23
CVE-2026-33650 [HIGH] CWE-863 CVE-2026-33650: WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privileges to perform full video management operations — including ownership transfer and deletion of any video — despite the permission being documented as only allowing video publicity changes (Active, Inactiv
ghsanvdosv
CVE-2026-33485P3HIGHCVSS 7.5≤ 26.02026-03-23
CVE-2026-33485 [HIGH] CWE-89 CVE-2026-33485: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_pub
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated directly into SQL queries in two locations — `LiveTransmitionHistory::getLatest()` and `LiveTransmition::keyE
ghsanvdosv
CVE-2026-86721P3HIGHCVSS 7.5≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86721 [HIGH] CWE-287 CVE-2026-86721: AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cook
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcas
nvd
CVE-2026-34732P3HIGHCVSS 7.5≤ 26.02026-03-31
CVE-2026-34732 [HIGH] CWE-306 CVE-2026-34732: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin te
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php both require admin privileges, the list.json.php template was shipped without this guard. Every plugin th
ghsanvdosv
CVE-2026-92915P3HIGHCVSS 7.3≤ 29.02026-09-17
CVE-2026-92915 [HIGH] CWE-770 CVE-2026-92915: WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id directly from the query string, and calls User::sendVerificationLink() with no session requirement, no CSRF/global
nvd
CVE-2020-23489P3HIGHCVSS 8.8fixed in 8.92020-11-16
CVE-2020-23489 [HIGH] CWE-862 CVE-2020-23489: The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
ghsanvdosv
CVE-2020-37158P3HIGHCVSS 8.8v8.12026-02-11
CVE-2020-37158 [HIGH] CWE-352 CVE-2020-37158: AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to res
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
nvd
CVE-2026-33043P3HIGHCVSS 8.1fixed in 26.02026-03-20
CVE-2026-33043 [HIGH] CWE-942 CVE-2026-33043: WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json
WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Access-Control-Allow-Origin with Access-Control-Allow-Credentials: true, enabling cross-origin session theft and full a
ghsanvdosv
CVE-2026-88865P3HIGHCVSS 8.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88865 [HIGH] CWE-639 CVE-2026-88865: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and publish to their YouTube, Twitch, o
nvd
CVE-2025-34438P3HIGHCVSS 8.1fixed in 20.02025-12-17
CVE-2025-34438 [HIGH] CWE-639 CVE-2025-34438: AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing use
AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce ownership or management rights for the targeted video.
nvd
CVE-2026-43885P3HIGHCVSS 7.7≤ 29.02026-05-11
CVE-2026-43885 [HIGH] CWE-200 CVE-2026-43885: WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticat
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b contains an updated fix.
ghsanvd
CVE-2026-39369P3HIGHCVSS 7.6≤ 26.02026-04-07
CVE-2026-39369 [HIGH] CWE-22 CVE-2026-39369: WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderRecei
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose server-local files through the GIF poster storage path. The vulnerable GIF branch could be abused to read
ghsanvd
CVE-2026-86727P3HIGHCVSS 7.5≤ 29.02026-09-08
CVE-2026-86727 [HIGH] CWE-306 CVE-2026-86727: AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php t
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSO
nvd
CVE-2026-92577P3HIGHCVSS 7.5≤ 29.02026-09-16
CVE-2026-92577 [HIGH] CWE-639 CVE-2026-92577: In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerabilit
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields including email, phone, address, b
nvd
CVE-2026-34733P3HIGHCVSS 7.3≤ 26.02026-03-31
CVE-2026-34733 [HIGH] CWE-284 CVE-2026-34733: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation sc
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively from the command line, but the guard condition !php_sapi_name() === 'cli' never evaluates to true due to
ghsanvdosv
CVE-2026-49279P3HIGHCVSS 7.2≥ 0, ≤ 29.02026-06-04
CVE-2026-49279 [HIGH] CWE-79 WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)
WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)
# AVideo: Stored XSS via `autoEvalCodeOnHTML` in MessageSQLite WebSocket Handler
## Summary
AVideo has a stored XSS vulnerability in the WebSocket messaging system. The `MessageSQLite.php` handler only strips `autoEvalCodeOnHTML` from `$json[
ghsa
CVE-2026-34394P3HIGHCVSS 8.1≤ 26.02026-03-31
CVE-2026-34394 [HIGH] CWE-352 CVE-2026-34394: WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin conf
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before processing the request. Combined with the application's explicit SameSite=None cookie policy, an attacker can forg
ghsanvdosv
CVE-2026-91965P3HIGHCVSS 7.5≤ 29.02026-09-15
CVE-2026-91965 [HIGH] CWE-200 CVE-2026-91965: WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by accessing these endpoints.
nvd