CVE-2026-33035
- EPSS 0.32%
- Veröffentlicht 20.03.2026 05:08:31
- Zuletzt bearbeitet 24.03.2026 16:30:45
WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser. User input from a URL parameter flows throug...
CVE-2026-30885
- EPSS 0.37%
- Veröffentlicht 09.03.2026 22:35:59
- Zuletzt bearbeitet 13.03.2026 15:20:47
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and...
CVE-2026-29058
- EPSS 2.13%
- Veröffentlicht 06.03.2026 07:16:02
- Zuletzt bearbeitet 10.03.2026 19:14:24
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server comp...
CVE-2026-28501
- EPSS 1.51%
- Veröffentlicht 06.03.2026 03:05:21
- Zuletzt bearbeitet 16.03.2026 15:06:55
WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the c...
CVE-2026-28502
- EPSS 0.67%
- Veröffentlicht 06.03.2026 03:04:57
- Zuletzt bearbeitet 16.03.2026 15:03:31
WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality. The issue allowed an authenticated administrat...
CVE-2026-29093
- EPSS 0.49%
- Veröffentlicht 06.03.2026 03:04:43
- Zuletzt bearbeitet 16.03.2026 14:49:52
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sess...
CVE-2026-27732
- EPSS 0.24%
- Veröffentlicht 24.02.2026 14:56:55
- Zuletzt bearbeitet 25.02.2026 16:52:33
WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and fetches the referenced resource server-side without proper validation or an allow-list. This allows a...
CVE-2026-27568
- EPSS 0.23%
- Veröffentlicht 24.02.2026 14:53:20
- Zuletzt bearbeitet 26.02.2026 19:57:52
WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Safe Mode enabled. Markdown links are not sufficiently sanitized, allowing `javascript:` URIs to be rend...
CVE-2020-37158
- EPSS 0.23%
- Veröffentlicht 11.02.2026 20:49:49
- Zuletzt bearbeitet 20.02.2026 16:21:56
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's r...
CVE-2020-37173
- EPSS 0.57%
- Veröffentlicht 11.02.2026 20:36:58
- Zuletzt bearbeitet 18.02.2026 19:36:51
AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, an...