Wwbn Avideo vulnerabilities
336 known vulnerabilities affecting wwbn/avideo.
Total CVEs
336
CISA KEV
0
Public exploits
10
Exploited in wild
2
Severity breakdown
CRITICAL33HIGH131MEDIUM171LOW1
Vulnerabilities
Page 9 of 17
CVE-2026-33354P3MEDIUMCVSS 6.5≤ 26.02026-03-23
CVE-2026-33354 [MEDIUM] CWE-73 CVE-2026-33354: WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/a
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that path to trusted server-generated chunk locations, the endpoint accepts arbitrary local filesystem paths that pass
ghsanvdosv
CVE-2026-39368P3MEDIUMCVSS 6.5≤ 26.02026-04-07
CVE-2026-39368 [MEDIUM] CWE-918 CVE-2026-39368: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log call
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamers. The vulnerable flow allowed a low-privilege user with streaming permission to store an arbitrary c
ghsanvd
CVE-2026-86186P3MEDIUMCVSS 6.5≤ 29.02026-09-05
CVE-2026-86186 [MEDIUM] CWE-307 CVE-2026-86186: AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attacker
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited password guessing attempts against any account from a single IP address
nvd
CVE-2026-33731P3MEDIUMCVSS 6.5fixed in 29.02026-07-16
CVE-2026-33731 [MEDIUM] CWE-345 CVE-2026-33731: WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook h
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that allows an attacker to forge webhook requests with arbitrary payment amounts and target user IDs. By supplying a valid transaction ID from a small legitimate purcha
ghsanvd
CVE-2026-40925P3HIGHCVSS 8.3≤ 29.02026-04-21
CVE-2026-40925 [HIGH] CWE-352 CVE-2026-40925: WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpda
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST` but protects the endpoint only with `User::isAdmin()`. It does not call `forbidIfIsUntrustedRequest()`, does not verify a `globalToken`, and does not va
nvd
CVE-2026-34375P3HIGHCVSS 8.2≤ 26.02026-03-27
CVE-2026-34375 [HIGH] CWE-79 CVE-2026-34375: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet St
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any encoding or sanitization. The `plugin` parameter is not included in any of the framework's input filter lists defined in `security.php`
ghsanvdosv
CVE-2026-85160P3HIGHCVSS 8.1≤ c91b5975d2026-09-03
CVE-2026-85160 [HIGH] CWE-73 CVE-2026-85160: AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerabili
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deleti
nvd
CVE-2026-39370P3HIGHCVSS 7.1≤ 26.02026-04-07
CVE-2026-39370 [HIGH] CVE-2026-39370: WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm to bypass SSRF validation. The server then fetches the response and stores it as media content. This allows an
ghsanvd
CVE-2025-34435P3MEDIUMCVSS 6.5fixed in 20.02025-12-17
CVE-2025-34435 [MEDIUM] CWE-639 CVE-2025-34435: AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allo
AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files belonging to other users. The affected endpoint validates authentication but fails to verify ownership or edit permissions for the targeted video.
nvd
CVE-2026-33723P3MEDIUMCVSS 6.5≤ 26.02026-03-23
CVE-2026-33723 [MEDIUM] CWE-89 CVE-2026-33723: WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concatenates the `$this->users_id` property directly into an INSERT SQL query without sanitization or parameterized binding. This property originates from `$_POST['user_id']` in both `subscribe.json.php` and `s
ghsanvdosv
CVE-2026-41057P3HIGHCVSS 7.1≤ 29.02026-04-21
CVE-2026-41057 [HIGH] CWE-346 CVE-2026-41057: WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation
WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1) `plugin/API/router.php` lines 4-8 unconditionally reflect any origin before application c
nvd
CVE-2026-40907P3MEDIUMCVSS 6.5≤ 29.02026-04-21
CVE-2026-40907 [MEDIUM] CWE-639 CVE-2026-40907: WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming permission to retrieve other users' live restream configurations, including third-party platform str
nvd
CVE-2026-34737P3MEDIUMCVSS 6.5≤ 26.02026-03-31
CVE-2026-34737 [MEDIUM] CWE-862 CVE-2026-34737: WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin inclu
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including cancellation. Due to a bug in the retrieveSubscripti
ghsanvdosv
CVE-2026-58002P3MEDIUMCVSS 6.5≤ 9c39d8c8b4c1f75540788d6b391740852ceb07322026-08-22
CVE-2026-58002 [MEDIUM] CWE-345 CVE-2026-58002: WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass
WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the counterparty's agreement timestamp. Attackers can create a forged affiliation with status='a' and then r
nvd
CVE-2026-105086P3HIGHCVSS 8.7≥ 12.4, ≤ 29.2.02026-10-04
CVE-2026-105086 [HIGH] CWE-79 CVE-2026-105086: WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows aut
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery
nvd
CVE-2026-105089P3HIGHCVSS 8.7≤ 29.2.02026-10-04
CVE-2026-105089 [HIGH] CWE-79 CVE-2026-105089: WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users wi
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScri
nvd
CVE-2026-83595P3HIGHCVSS 8.1≤ 29.02026-09-01
CVE-2026-83595 [HIGH] CWE-352 CVE-2026-83595: AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows at
AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to delete videos, deactivate accounts, or modify playlists without user inte
nvd
CVE-2022-32761P3MEDIUMCVSS 6.5v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-32761 [MEDIUM] CWE-73 CVE-2022-32761: An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWB
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2022-28710P3MEDIUMCVSS 6.5v11.6vdev master commit 3f7c03642022-08-22
CVE-2022-28710 [MEDIUM] CWE-73 CVE-2022-28710: An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 an
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2023-49810P3MEDIUMCVSS 6.5v15fed957fbvdev master commit 15fed957fb2024-01-10
CVE-2023-49810 [MEDIUM] CWE-307 CVE-2023-49810: A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of W
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute force user credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
ghsanvdosv