CVE-2026-55173
- EPSS 2.16%
- Veröffentlicht 16.07.2026 20:41:26
- Zuletzt bearbeitet 17.07.2026 18:36:41
WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single & ( the shell background operator). CVE-2026-3348...
CVE-2026-33692
- EPSS 0.27%
- Veröffentlicht 16.07.2026 20:27:04
- Zuletzt bearbeitet 17.07.2026 18:36:41
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache ...
CVE-2026-63304
- EPSS 1.36%
- Veröffentlicht 16.07.2026 12:19:16
- Zuletzt bearbeitet 20.07.2026 23:16:57
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can cr...
CVE-2026-63305
- EPSS 1.38%
- Veröffentlicht 16.07.2026 12:19:16
- Zuletzt bearbeitet 20.07.2026 23:16:57
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can ...
CVE-2026-54458
- EPSS 0.3%
- Veröffentlicht 15.07.2026 21:33:27
- Zuletzt bearbeitet 16.07.2026 16:19:13
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin of ...
CVE-2026-50183
- EPSS 0.16%
- Veröffentlicht 15.07.2026 21:13:06
- Zuletzt bearbeitet 16.07.2026 14:16:52
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data API into the homepage gallery ...
CVE-2026-50182
- EPSS 0.18%
- Veröffentlicht 15.07.2026 21:04:26
- Zuletzt bearbeitet 17.07.2026 13:18:56
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenated directly into the href attri...
CVE-2026-49279
- EPSS 0.33%
- Veröffentlicht 15.07.2026 20:57:21
- Zuletzt bearbeitet 18.07.2026 03:16:36
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML fro...
CVE-2026-33684
- EPSS 0.21%
- Veröffentlicht 15.07.2026 20:47:45
- Zuletzt bearbeitet 16.07.2026 14:16:50
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during accou...
CVE-2026-56347
- EPSS 0.26%
- Veröffentlicht 20.06.2026 18:27:13
- Zuletzt bearbeitet 22.06.2026 19:17:30
AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped ...