CVE-2026-35180
- EPSS 0.02%
- Veröffentlicht 06.04.2026 19:06:46
- Zuletzt bearbeitet 15.04.2026 18:42:29
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-bas...
CVE-2026-35179
- EPSS 0.05%
- Veröffentlicht 06.04.2026 19:05:49
- Zuletzt bearbeitet 07.04.2026 13:20:11
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts use...
CVE-2026-34740
- EPSS 0.03%
- Veröffentlicht 31.03.2026 20:57:14
- Zuletzt bearbeitet 01.04.2026 18:43:31
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page v...
CVE-2026-34739
- EPSS 0.03%
- Veröffentlicht 31.03.2026 20:56:16
- Zuletzt bearbeitet 01.04.2026 18:42:45
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other output encodin...
CVE-2026-34738
- EPSS 0.03%
- Veröffentlicht 31.03.2026 20:55:09
- Zuletzt bearbeitet 01.04.2026 18:42:05
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active" (a). This...
CVE-2026-34737
- EPSS 0.03%
- Veröffentlicht 31.03.2026 20:53:51
- Zuletzt bearbeitet 01.04.2026 18:45:32
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads...
CVE-2026-34733
- EPSS 0.07%
- Veröffentlicht 31.03.2026 20:52:45
- Zuletzt bearbeitet 01.04.2026 18:40:28
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively f...
CVE-2026-34732
- EPSS 0.05%
- Veröffentlicht 31.03.2026 20:51:51
- Zuletzt bearbeitet 01.04.2026 18:38:07
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php bo...
CVE-2026-34731
- EPSS 0.17%
- Veröffentlicht 31.03.2026 20:50:23
- Zuletzt bearbeitet 01.04.2026 18:37:42
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthenticated users to terminate any active live stream. The endpoint processes RTMP callback events to mark...
CVE-2026-34716
- EPSS 0.05%
- Veröffentlicht 31.03.2026 20:49:21
- Zuletzt bearbeitet 01.04.2026 18:37:08
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the heading parame...