CVE-2026-72748
- EPSS 0.66%
- Veröffentlicht 11.08.2026 12:17:02
- Zuletzt bearbeitet 11.08.2026 15:17:35
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authenticat...
CVE-2026-72747
- EPSS 0.26%
- Veröffentlicht 11.08.2026 12:17:01
- Zuletzt bearbeitet 11.08.2026 18:18:24
AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is re...
CVE-2026-64625
- EPSS 0.35%
- Veröffentlicht 20.07.2026 21:50:54
- Zuletzt bearbeitet 23.07.2026 15:23:01
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plug...
CVE-2026-64626
- EPSS 0.19%
- Veröffentlicht 20.07.2026 21:50:54
- Zuletzt bearbeitet 23.07.2026 15:23:01
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can s...
CVE-2026-33731
- EPSS 0.14%
- Veröffentlicht 16.07.2026 20:46:53
- Zuletzt bearbeitet 17.07.2026 18:36:41
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that allows an attacker to forge webhook requests with arbitrary pa...
CVE-2026-55173
- EPSS 2.16%
- Veröffentlicht 16.07.2026 20:41:26
- Zuletzt bearbeitet 17.07.2026 18:36:41
WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single & ( the shell background operator). CVE-2026-3348...
CVE-2026-33692
- EPSS 0.27%
- Veröffentlicht 16.07.2026 20:27:04
- Zuletzt bearbeitet 17.07.2026 18:36:41
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache ...
CVE-2026-63304
- EPSS 1.36%
- Veröffentlicht 16.07.2026 12:19:16
- Zuletzt bearbeitet 20.07.2026 23:16:57
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can cr...
CVE-2026-63305
- EPSS 1.38%
- Veröffentlicht 16.07.2026 12:19:16
- Zuletzt bearbeitet 20.07.2026 23:16:57
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can ...
CVE-2026-54458
- EPSS 0.3%
- Veröffentlicht 15.07.2026 21:33:27
- Zuletzt bearbeitet 16.07.2026 16:19:13
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin of ...