Wwbn

Avideo

220 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.64%
  • Veröffentlicht 23.03.2026 18:23:20
  • Zuletzt bearbeitet 25.03.2026 17:54:10

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using `finfo` MIME type detection but derives the saved filename extension from the user-supplie...

Exploit
  • EPSS 0.74%
  • Veröffentlicht 23.03.2026 18:21:59
  • Zuletzt bearbeitet 25.03.2026 17:52:58

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, s...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.03.2026 18:17:47
  • Zuletzt bearbeitet 25.03.2026 17:51:40

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued publicly (e.g., `...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 23.03.2026 16:32:28
  • Zuletzt bearbeitet 24.03.2026 16:55:37

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. ...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 23.03.2026 16:29:47
  • Zuletzt bearbeitet 24.03.2026 17:01:02

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrar...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 23.03.2026 16:28:20
  • Zuletzt bearbeitet 24.03.2026 18:08:01

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated users to retri...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 23.03.2026 16:24:52
  • Zuletzt bearbeitet 24.03.2026 18:11:11

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `<a>` and `<img>` tags in comments, but ex...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 23.03.2026 16:11:57
  • Zuletzt bearbeitet 24.03.2026 18:11:56

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` parameter directly into an HTML `<input>` tag's attributes...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 23.03.2026 15:52:33
  • Zuletzt bearbeitet 24.03.2026 18:17:24

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `objects/listF...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 23.03.2026 15:25:27
  • Zuletzt bearbeitet 24.03.2026 17:47:58

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration b...