cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 7 of 17
CVE-2026-81678P3HIGHCVSS 7.5fixed in 24.02026-08-27
CVE-2026-81678 [HIGH] CWE-918 CVE-2026-81678: AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL functio AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinks proxy endpoint to reach internal services and cloud metadata endpoints
nvd
CVE-2026-33512P3HIGHCVSS 7.5≤ 26.02026-03-23
CVE-2026-33512 [HIGH] CWE-287 CVE-2026-33512: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin e WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued publicly (e.g., `view/url2Embed.json.php`), so any user can recover protected tokens/metadata. Commit 3fdeecef37bb88967a
ghsanvdosv
CVE-2026-33867P3HIGHCVSS 7.5≤ 26.02026-03-27
CVE-2026-33867 [HIGH] CWE-312 CVE-2026-33867: WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows co WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the database (via SQL injection, a database backup, or mis
ghsanvdosv
CVE-2026-81732P3MEDIUMCVSS 6.9≤ 30.02026-08-28
CVE-2026-81732 [MEDIUM] CWE-200 CVE-2026-81732: WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4 WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.
nvd
CVE-2022-29468P3HIGHCVSS 8.8v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-29468 [HIGH] CWE-352 CVE-2022-29468: A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3 A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
nvd
CVE-2026-84482P3HIGHCVSS 8.8≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-09-01
CVE-2026-84482 [HIGH] CWE-346 CVE-2026-84482: WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_d WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration cha
nvd
CVE-2025-25214P3HIGHCVSS 7.5v14.4vdev master commit 8a8954ff2025-07-24
CVE-2025-25214 [HIGH] CWE-362 CVE-2025-25214: A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVid A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HTTP request can lead to arbitrary code execution.
nvd
CVE-2026-33681P3HIGHCVSS 7.2≤ 26.02026-03-23
CVE-2026-33681 [HIGH] CWE-22 CVE-2026-33681: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/plu WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a `name` parameter via POST and passes it to `Plugin::getDatabaseFileName()` without any path traversal sanitization. This allows an authenticated admin (or an attacker via CSRF) to traverse outside the plu
ghsanvdosv
CVE-2026-40909P3MEDIUMCVSS 6.5≤ 29.02026-04-21
CVE-2026-40909 [MEDIUM] CWE-22 CVE-2026-40909: WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint ( WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['code']` parameter is then written verbatim to that path via `fwrite()` at line 40. An admin attacker (o
nvd
CVE-2026-43884P3HIGHCVSS 7.7≤ 29.02026-05-11
CVE-2026-43884 [HIGH] CWE-918 CVE-2026-43884: WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (p WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (plugin/AI/receiveAsync.json.php and objects/EpgParser.php) in AVideo call isSSRFSafeURL() to validate user-supplied URLs, then fetch them using bare file_get_contents() without disabling PHP's automatic redirect following. An attacker can supply a URL po
ghsanvd
CVE-2026-33492P3HIGHCVSS 7.3≤ 26.02026-03-23
CVE-2026-33492 [HIGH] CWE-384 CVE-2026-33492: WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_sessi WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration bypass exists for specific blacklisted endpoints when the request originates from the same domain. Combi
ghsanvdosv
CVE-2026-41062P3MEDIUMCVSS 6.5≤ 29.02026-04-21
CVE-2026-41062 [MEDIUM] CWE-22 CVE-2026-41062: WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fi WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks the URL path component (via `parse_url($url, PHP_URL_PATH)`) for `..` sequences. However, the downstream function `try_get_contents_from_local()` in `objects/
nvd
CVE-2020-23490P3HIGHCVSS 7.5fixed in 8.92020-11-16
CVE-2020-23490 [HIGH] CVE-2020-23490: There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthen There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
nvd
CVE-2022-28712P3CRITICALCVSS 9.0v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-28712 [CRITICAL] CWE-79 CVE-2022-28712: A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11 A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
nvd
CVE-2026-84476P3HIGHCVSS 7.5≤ 29.02026-09-01
CVE-2026-84476 [HIGH] CWE-290 CVE-2026-84476: WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.
nvd
CVE-2026-43874P3HIGHCVSS 7.2≤ 29.02026-05-11
CVE-2026-43874 [HIGH] CWE-94 CVE-2026-43874: WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML eval sink (from CVE-2026-40911) only strips the payload when it sits under $json['msg'], but the relay function msgToResourceId() selects the outbound message from $msg['json'] before $msg['msg']. An unauthe
ghsanvd
CVE-2026-89242P3HIGHCVSS 7.2≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89242 [HIGH] CWE-918 CVE-2026-89242: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request f WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can POST file paths or HTTP URLs to login.json.php to read local files or access internal services, with r
nvd
CVE-2026-89254P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89254 [HIGH] CWE-79 CVE-2026-89254: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php endpoint that execute when viewing extra info pages or profile forms that rend
nvd
CVE-2022-26842P3CRITICALCVSS 9.6v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-26842 [CRITICAL] CWE-79 CVE-2022-26842: A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionalit A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
nvd
CVE-2023-49738P3HIGHCVSS 7.5v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49738 [HIGH] CWE-73 CVE-2023-49738: An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo d An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
nvd
Wwbn Avideo vulnerabilities | cvebase