CVE-2026-82647
- EPSS 0.1%
- Veröffentlicht 30.08.2026 14:33:30
- Zuletzt bearbeitet 31.08.2026 20:56:08
WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malic...
CVE-2026-82646
- EPSS 0.16%
- Veröffentlicht 30.08.2026 14:33:29
- Zuletzt bearbeitet 31.08.2026 20:56:08
WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evid...
CVE-2026-82644
- EPSS 0.26%
- Veröffentlicht 30.08.2026 14:33:28
- Zuletzt bearbeitet 01.09.2026 15:17:35
WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal)...
CVE-2026-82645
- EPSS 0.13%
- Veröffentlicht 30.08.2026 14:33:28
- Zuletzt bearbeitet 31.08.2026 20:56:08
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ...
CVE-2026-82643
- EPSS 0.2%
- Veröffentlicht 30.08.2026 14:33:27
- Zuletzt bearbeitet 02.09.2026 16:17:26
WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger uncapped two-...
CVE-2026-81733
- EPSS 0.17%
- Veröffentlicht 28.08.2026 10:49:23
- Zuletzt bearbeitet 29.08.2026 12:16:57
WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and ...
CVE-2026-81732
- EPSS 0.4%
- Veröffentlicht 28.08.2026 10:49:22
- Zuletzt bearbeitet 29.08.2026 12:16:56
WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve...
CVE-2026-81678
- EPSS 0.33%
- Veröffentlicht 27.08.2026 14:50:45
- Zuletzt bearbeitet 29.08.2026 12:16:55
AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSR...
CVE-2026-57944
- EPSS 0.1%
- Veröffentlicht 22.08.2026 13:16:38
- Zuletzt bearbeitet 26.08.2026 18:16:41
AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cr...
CVE-2026-58001
- EPSS 0.11%
- Veröffentlicht 22.08.2026 13:16:38
- Zuletzt bearbeitet 26.08.2026 17:17:08
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfer...