CVE-2026-45580
- EPSS 0.14%
- Veröffentlicht 29.05.2026 13:14:49
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, witho...
CVE-2026-45578
- EPSS 0.32%
- Veröffentlicht 29.05.2026 13:14:02
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-qu...
CVE-2026-45610
- EPSS 0.11%
- Veröffentlicht 29.05.2026 13:13:08
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getI...
CVE-2026-45619
- EPSS 0.14%
- Veröffentlicht 29.05.2026 13:11:37
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS pinning via CURLOPT_RESOLVE, opening DNS-rebinding ...
CVE-2026-45620
- EPSS 0.19%
- Veröffentlicht 29.05.2026 13:07:19
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenti...
CVE-2026-45731
- EPSS 0.47%
- Veröffentlicht 29.05.2026 13:05:02
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticate...
CVE-2026-46337
- EPSS 0.46%
- Veröffentlicht 29.05.2026 13:03:01
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that the PHP user can open — including private user-profile photos that the application's normal ser...
CVE-2026-47694
- EPSS 0.16%
- Veröffentlicht 29.05.2026 13:00:37
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScri...
CVE-2026-47696
- EPSS 0.12%
- Veröffentlicht 29.05.2026 12:59:30
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST parameter. The endpoint contains a TODO for real Auth...
CVE-2026-43885
- EPSS 0.26%
- Veröffentlicht 11.05.2026 20:45:21
- Zuletzt bearbeitet 15.05.2026 19:16:58
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f...