CVE-2026-33041
- EPSS 0.33%
- Veröffentlicht 20.03.2026 05:50:07
- Zuletzt bearbeitet 23.03.2026 16:15:03
WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing algorithm to any unauthenticated user. An attacker can submit arbitrary passwords and receive their has...
CVE-2026-33039
- EPSS 0.45%
- Veröffentlicht 20.03.2026 05:38:50
- Zuletzt bearbeitet 23.03.2026 16:22:49
WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal/private networks using isSSRFSafeURL(), but only checks the initial URL. When the initial ...
CVE-2026-33038
- EPSS 0.49%
- Veröffentlicht 20.03.2026 05:35:56
- Zuletzt bearbeitet 23.03.2026 16:24:08
WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfiguration.php endpoint. install/checkConfiguration.php performs full application initialization:...
CVE-2026-33037
- EPSS 0.67%
- Veröffentlicht 20.03.2026 05:25:49
- Zuletzt bearbeitet 23.03.2026 16:25:29
WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship with the admin password set to "password", which is automatically used to seed the admin account dur...
CVE-2026-33035
- EPSS 0.32%
- Veröffentlicht 20.03.2026 05:08:31
- Zuletzt bearbeitet 24.03.2026 16:30:45
WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser. User input from a URL parameter flows throug...
CVE-2026-30885
- EPSS 0.37%
- Veröffentlicht 09.03.2026 22:35:59
- Zuletzt bearbeitet 13.03.2026 15:20:47
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate user IDs and...
CVE-2026-29058
- EPSS 2.13%
- Veröffentlicht 06.03.2026 07:16:02
- Zuletzt bearbeitet 10.03.2026 19:14:24
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server comp...
CVE-2026-28501
- EPSS 1.51%
- Veröffentlicht 06.03.2026 03:05:21
- Zuletzt bearbeitet 16.03.2026 15:06:55
WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the c...
CVE-2026-28502
- EPSS 0.67%
- Veröffentlicht 06.03.2026 03:04:57
- Zuletzt bearbeitet 16.03.2026 15:03:31
WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality. The issue allowed an authenticated administrat...
CVE-2026-29093
- EPSS 0.49%
- Veröffentlicht 06.03.2026 03:04:43
- Zuletzt bearbeitet 16.03.2026 14:49:52
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store all user sess...