CVE-2026-58002
- EPSS 0.14%
- Veröffentlicht 22.08.2026 13:16:38
- Zuletzt bearbeitet 26.08.2026 17:10:09
WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the cou...
CVE-2026-58003
- EPSS 0.11%
- Veröffentlicht 22.08.2026 13:16:38
- Zuletzt bearbeitet 26.08.2026 17:07:30
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying ...
CVE-2026-59256
- EPSS 0.27%
- Veröffentlicht 22.08.2026 13:16:38
- Zuletzt bearbeitet 26.08.2026 18:16:42
WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Atta...
CVE-2026-59808
- EPSS 0.34%
- Veröffentlicht 22.08.2026 13:16:38
- Zuletzt bearbeitet 26.08.2026 17:07:30
AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts ...
CVE-2026-56380
- EPSS 0.21%
- Veröffentlicht 22.08.2026 13:16:37
- Zuletzt bearbeitet 26.08.2026 17:07:30
AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all ...
CVE-2026-72748
- EPSS 0.66%
- Veröffentlicht 11.08.2026 12:17:02
- Zuletzt bearbeitet 08.09.2026 20:32:39
AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authenticat...
CVE-2026-72747
- EPSS 0.26%
- Veröffentlicht 11.08.2026 12:17:01
- Zuletzt bearbeitet 08.09.2026 20:32:39
AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is re...
CVE-2026-64625
- EPSS 0.35%
- Veröffentlicht 20.07.2026 21:50:54
- Zuletzt bearbeitet 23.07.2026 15:23:01
AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plug...
CVE-2026-64626
- EPSS 0.19%
- Veröffentlicht 20.07.2026 21:50:54
- Zuletzt bearbeitet 23.07.2026 15:23:01
AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can s...
CVE-2026-33731
- EPSS 0.14%
- Veröffentlicht 16.07.2026 20:46:53
- Zuletzt bearbeitet 17.07.2026 18:36:41
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that allows an attacker to forge webhook requests with arbitrary pa...