cbcvebase.

Wwbn Avideo vulnerabilities

336 known vulnerabilities affecting wwbn/avideo.

Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1

Vulnerabilities

Page 8 of 17
CVE-2020-37173P3HIGHCVSS 7.5v8.12026-02-11
CVE-2020-37173 [HIGH] CWE-359 CVE-2020-37173: AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumer AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by manipulating the users_id parameter.
nvd
CVE-2025-41420P3CRITICALCVSS 9.6v14.4vdev master commit 8a8954ff2025-07-24
CVE-2025-41420 [CRITICAL] CWE-79 CVE-2025-41420: A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2026-86725P3HIGHCVSS 7.1≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-08
CVE-2026-86725 [HIGH] CWE-639 CVE-2026-86725: AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerabili AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored access_token and refresh_token, then dele
nvd
CVE-2026-85164P3HIGHCVSS 7.1≤ c91b5975d2026-09-03
CVE-2026-85164 [HIGH] CWE-918 CVE-2026-85164: WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadata or internal services, with responses written to publicly accessible we
nvd
CVE-2026-34740P3MEDIUMCVSS 6.5≤ 26.02026-03-31
CVE-2026-34740 [MEDIUM] CWE-918 CVE-2026-34740: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Progra WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The URL is validated only with PHP's FILTER_VALIDATE_URL, which accepts internal network addres
ghsanvdosv
CVE-2026-88866P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88866 [HIGH] CWE-79 CVE-2026-88866: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scr WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator brow
nvd
CVE-2026-89249P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89249 [HIGH] CWE-79 CVE-2026-89249: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators viewing pending withdrawal requests in pendingRequests.php execute the stored
nvd
CVE-2026-89253P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89253 [HIGH] CWE-79 CVE-2026-89253: WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scr WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(..., FILTER_VALIDATE_URL), which accepts strings such as http://evil.example/"onmouseo
nvd
CVE-2026-89256P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89256 [HIGH] CWE-79 CVE-2026-89256: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every visitor of that video executes the pay
nvd
CVE-2026-89255P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-11
CVE-2026-89255 [HIGH] CWE-79 CVE-2026-89255: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's sessio
nvd
CVE-2026-88868P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88868 [HIGH] CWE-79 CVE-2026-88868: AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scriptin AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including a
nvd
CVE-2026-88867P3HIGHCVSS 8.7≤ c3edcc274c389816d434acadac07ee78eaf330c12026-09-10
CVE-2026-88867 [HIGH] CWE-79 CVE-2026-88867: WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contai WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Category::setName() and Category::setIconClass(), which store the values without sanitization (setName only truncates to
nvd
CVE-2022-32777P3HIGHCVSS 7.5v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32777 [HIGH] CWE-732 CVE-2022-32777: An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and d An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. Thi
nvd
CVE-2022-32778P3HIGHCVSS 7.5v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32778 [HIGH] CWE-732 CVE-2022-32778: An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and d An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. Thi
nvd
CVE-2025-36548P3CRITICALCVSS 9.6v14.4vdev master commit 8a8954ff2025-07-24
CVE-2025-36548 [CRITICAL] CWE-79 CVE-2025-36548: A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri paramete A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
nvd
CVE-2026-86188P3HIGHCVSS 7.2≤ 29.02026-09-05
CVE-2026-86188 [HIGH] CWE-79 CVE-2026-86188: AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthen AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names resolving to global functions like avideoConfirmHTML that accept untrusted dat
nvd
CVE-2026-72747P3HIGHCVSS 7.2v29.02026-08-11
CVE-2026-72747 [HIGH] CWE-79 CVE-2026-72747: AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attacker AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.
nvd
CVE-2026-84481P3MEDIUMCVSS 6.9≤ 30.02026-09-01
CVE-2026-84481 [MEDIUM] CWE-200 CVE-2026-84481: WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugi WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configu
nvd
CVE-2026-41060P3MEDIUMCVSS 6.5≤ 29.02026-04-21
CVE-2026-41060 [MEDIUM] CWE-918 CVE-2026-41060: WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` func WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows any URL whose hostname matches `webSiteRootURL` to bypass all SSRF protections. Because the check compares only the hostname and ignores the port, an att
nvd
CVE-2026-85163P3MEDIUMCVSS 6.5≤ c91b5975d2026-09-03
CVE-2026-85163 [MEDIUM] CWE-918 CVE-2026-85163: AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG pars AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during video upload, which is validated only for syntax and later fetched server-side during EPG generation with
nvd
Wwbn Avideo vulnerabilities | cvebase