CVE-2026-39370
- EPSS 0.03%
- Veröffentlicht 07.04.2026 19:26:27
- Zuletzt bearbeitet 08.04.2026 21:27:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm...
CVE-2026-39369
- EPSS 0.05%
- Veröffentlicht 07.04.2026 19:24:33
- Zuletzt bearbeitet 08.04.2026 21:27:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose s...
CVE-2026-39368
- EPSS 0.03%
- Veröffentlicht 07.04.2026 19:23:29
- Zuletzt bearbeitet 08.04.2026 21:27:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamer...
CVE-2026-39367
- EPSS 0.03%
- Veröffentlicht 07.04.2026 19:22:07
- Zuletzt bearbeitet 08.04.2026 21:27:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A use...
CVE-2026-39366
- EPSS 0.01%
- Veröffentlicht 07.04.2026 19:21:12
- Zuletzt bearbeitet 08.04.2026 21:27:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate...
CVE-2026-35452
- EPSS 0.04%
- Veröffentlicht 06.04.2026 21:47:45
- Zuletzt bearbeitet 14.04.2026 15:37:41
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces Use...
CVE-2026-35450
- EPSS 0.04%
- Veröffentlicht 06.04.2026 21:46:54
- Zuletzt bearbeitet 14.04.2026 15:37:29
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg manag...
CVE-2026-35449
- EPSS 0.04%
- Veröffentlicht 06.04.2026 21:46:07
- Zuletzt bearbeitet 07.04.2026 14:16:23
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, ...
CVE-2026-35448
- EPSS 0.04%
- Veröffentlicht 06.04.2026 21:45:01
- Zuletzt bearbeitet 14.04.2026 19:57:27
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an AJAX pollin...
CVE-2026-35181
- EPSS 0.02%
- Veröffentlicht 06.04.2026 19:09:45
- Zuletzt bearbeitet 14.04.2026 19:57:50
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based securi...