CVE-2026-33716
- EPSS 0.44%
- Veröffentlicht 23.03.2026 18:46:47
- Zuletzt bearbeitet 25.03.2026 15:05:05
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the...
CVE-2026-33690
- EPSS 0.18%
- Veröffentlicht 23.03.2026 18:45:25
- Zuletzt bearbeitet 25.03.2026 15:06:07
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client's IP address. An attacker can spoof their IP add...
CVE-2026-33688
- EPSS 0.28%
- Veröffentlicht 23.03.2026 18:43:59
- Zuletzt bearbeitet 25.03.2026 18:05:21
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allows an unauth...
CVE-2026-33685
- EPSS 0.32%
- Veröffentlicht 23.03.2026 18:42:45
- Zuletzt bearbeitet 25.03.2026 19:04:36
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no authentication or authorization checks, allowing any unauthenticated attacker to extract ad campaign anal...
CVE-2026-33683
- EPSS 0.18%
- Veröffentlicht 23.03.2026 18:41:13
- Zuletzt bearbeitet 25.03.2026 18:04:29
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "about" field allows any registered user to inject arbitrary JavaScript that executes when other users vis...
CVE-2026-33681
- EPSS 0.49%
- Veröffentlicht 23.03.2026 18:39:33
- Zuletzt bearbeitet 25.03.2026 18:03:12
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a `name` parameter via POST and passes it to `Plugin::getDatabaseFileName()` without any path traversa...
CVE-2026-33651
- EPSS 0.35%
- Veröffentlicht 23.03.2026 18:38:22
- Zuletzt bearbeitet 25.03.2026 18:02:12
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint passes `$_REQUEST['live_schedule_id']` through multiple functions without sanitization until it reaches `Scheduler_commands::getAllAc...
CVE-2026-33650
- EPSS 0.24%
- Veröffentlicht 23.03.2026 18:28:13
- Zuletzt bearbeitet 25.03.2026 18:00:14
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privileges to perform full video management operations — including ownership transfer and deletion of any v...
CVE-2026-33649
- EPSS 0.17%
- Veröffentlicht 23.03.2026 18:26:32
- Zuletzt bearbeitet 25.03.2026 14:54:19
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has ...
CVE-2026-33648
- EPSS 0.61%
- Veröffentlicht 23.03.2026 18:25:07
- Zuletzt bearbeitet 25.03.2026 17:55:16
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-controlled `users_id` and `liveTransmitionHistory_id` values from the JSON request body without a...