Wwbn

Avideo

206 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.03.2026 14:08:49
  • Zuletzt bearbeitet 24.03.2026 18:46:11

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`). The unauthenticated `plugin/LiveLinks/proxy.php` endpoin...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 23.03.2026 14:05:55
  • Zuletzt bearbeitet 24.03.2026 18:48:38

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user input from `$_REQUEST['sections']` array values directly into PHP's `eval()` function. While...

Exploit
  • EPSS 13.27%
  • Veröffentlicht 23.03.2026 14:01:19
  • Zuletzt bearbeitet 24.03.2026 18:51:55

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 23.03.2026 13:58:13
  • Zuletzt bearbeitet 24.03.2026 18:57:18

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that path to tru...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 23.03.2026 13:53:47
  • Zuletzt bearbeitet 23.03.2026 15:56:03

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowCats` request parameter is sanitized only by stripp...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 23.03.2026 13:51:43
  • Zuletzt bearbeitet 23.03.2026 15:57:06

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 23.03.2026 13:46:17
  • Zuletzt bearbeitet 23.03.2026 15:58:42

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password valu...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 22.03.2026 17:17:09
  • Zuletzt bearbeitet 24.03.2026 17:53:43

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly i...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 22.03.2026 17:17:09
  • Zuletzt bearbeitet 24.03.2026 17:52:46

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.location` assignm...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 22.03.2026 16:58:09
  • Zuletzt bearbeitet 24.03.2026 21:14:36

WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other U...