Wwbn

Avideo

220 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.34%
  • Veröffentlicht 23.03.2026 13:46:17
  • Zuletzt bearbeitet 23.03.2026 15:58:42

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password valu...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 22.03.2026 17:17:09
  • Zuletzt bearbeitet 24.03.2026 17:53:43

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly i...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 22.03.2026 17:17:09
  • Zuletzt bearbeitet 24.03.2026 17:52:46

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.location` assignm...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 22.03.2026 16:58:09
  • Zuletzt bearbeitet 24.03.2026 21:14:36

WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other U...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 22.03.2026 16:35:16
  • Zuletzt bearbeitet 24.03.2026 21:14:05

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credentials can us...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 22.03.2026 16:29:08
  • Zuletzt bearbeitet 24.03.2026 19:07:50

WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, wit...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 22.03.2026 16:26:08
  • Zuletzt bearbeitet 23.03.2026 16:18:24

WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 20.03.2026 23:31:35
  • Zuletzt bearbeitet 13.04.2026 18:16:29

WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob()` without restricting the path to an allowed base directory. An authenticated uplo...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 20.03.2026 23:30:04
  • Zuletzt bearbeitet 13.04.2026 18:16:29

WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by `isValidURL...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 20.03.2026 05:52:59
  • Zuletzt bearbeitet 23.03.2026 15:28:09

WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Access-Control-A...