CVE-2026-33488
- EPSS 0.25%
- Veröffentlicht 23.03.2026 15:23:01
- Zuletzt bearbeitet 24.03.2026 17:49:58
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who ob...
CVE-2026-33485
- EPSS 0.47%
- Veröffentlicht 23.03.2026 14:14:15
- Zuletzt bearbeitet 24.03.2026 18:35:45
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated direc...
CVE-2026-33483
- EPSS 0.61%
- Veröffentlicht 23.03.2026 14:12:05
- Zuletzt bearbeitet 24.03.2026 18:36:55
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An unauthentic...
CVE-2026-33482
- EPSS 4.2%
- Veröffentlicht 23.03.2026 14:10:10
- Zuletzt bearbeitet 24.03.2026 18:41:00
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous ...
CVE-2026-33480
- EPSS 0.32%
- Veröffentlicht 23.03.2026 14:08:49
- Zuletzt bearbeitet 24.03.2026 18:46:11
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`). The unauthenticated `plugin/LiveLinks/proxy.php` endpoin...
CVE-2026-33479
- EPSS 0.53%
- Veröffentlicht 23.03.2026 14:05:55
- Zuletzt bearbeitet 24.03.2026 18:48:38
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user input from `$_REQUEST['sections']` array values directly into PHP's `eval()` function. While...
- EPSS 13.27%
- Veröffentlicht 23.03.2026 14:01:19
- Zuletzt bearbeitet 24.03.2026 18:51:55
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json...
CVE-2026-33354
- EPSS 0.25%
- Veröffentlicht 23.03.2026 13:58:13
- Zuletzt bearbeitet 24.03.2026 18:57:18
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that path to tru...
CVE-2026-33352
- EPSS 0.43%
- Veröffentlicht 23.03.2026 13:53:47
- Zuletzt bearbeitet 23.03.2026 15:56:03
WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowCats` request parameter is sanitized only by stripp...
CVE-2026-33351
- EPSS 0.43%
- Veröffentlicht 23.03.2026 13:51:43
- Zuletzt bearbeitet 23.03.2026 15:57:06
WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended...