Wwbn

Avideo

345 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 04.10.2026 15:10:23
  • Zuletzt bearbeitet 06.10.2026 15:25:00

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities a...

  • EPSS 0.23%
  • Veröffentlicht 04.10.2026 15:04:53
  • Zuletzt bearbeitet 06.10.2026 22:17:01

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel ...

  • EPSS 0.18%
  • Veröffentlicht 26.09.2026 13:23:06
  • Zuletzt bearbeitet 04.10.2026 00:16:35

AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that ...

  • EPSS 0.33%
  • Veröffentlicht 17.09.2026 11:16:43
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass ...

  • EPSS 0.31%
  • Veröffentlicht 17.09.2026 11:16:43
  • Zuletzt bearbeitet 22.09.2026 20:43:58

WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id directly fro...

  • EPSS 0.51%
  • Veröffentlicht 17.09.2026 11:16:42
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in objects/functions.php derives the code entirely fro...

  • EPSS 0.23%
  • Veröffentlicht 17.09.2026 11:16:41
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers who know the ...

  • EPSS 0.16%
  • Veröffentlicht 16.09.2026 21:46:52
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like a...

  • EPSS 0.16%
  • Veröffentlicht 16.09.2026 21:46:52
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers...

  • EPSS 0.2%
  • Veröffentlicht 16.09.2026 21:46:51
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (...