CVE-2026-105086
- EPSS 0.23%
- Veröffentlicht 04.10.2026 15:10:23
- Zuletzt bearbeitet 06.10.2026 15:25:00
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities a...
CVE-2026-105089
- EPSS 0.23%
- Veröffentlicht 04.10.2026 15:04:53
- Zuletzt bearbeitet 06.10.2026 22:17:01
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel ...
CVE-2026-100630
- EPSS 0.18%
- Veröffentlicht 26.09.2026 13:23:06
- Zuletzt bearbeitet 04.10.2026 00:16:35
AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that ...
CVE-2026-92914
- EPSS 0.33%
- Veröffentlicht 17.09.2026 11:16:43
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass ...
CVE-2026-92915
- EPSS 0.31%
- Veröffentlicht 17.09.2026 11:16:43
- Zuletzt bearbeitet 22.09.2026 20:43:58
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id directly fro...
CVE-2026-92913
- EPSS 0.51%
- Veröffentlicht 17.09.2026 11:16:42
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely fro...
CVE-2026-92912
- EPSS 0.23%
- Veröffentlicht 17.09.2026 11:16:41
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers who know the ...
CVE-2026-92585
- EPSS 0.16%
- Veröffentlicht 16.09.2026 21:46:52
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like a...
CVE-2026-92586
- EPSS 0.16%
- Veröffentlicht 16.09.2026 21:46:52
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers...
CVE-2026-92584
- EPSS 0.2%
- Veröffentlicht 16.09.2026 21:46:51
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (...