CVE-2026-92582
- EPSS 0.12%
- Veröffentlicht 16.09.2026 21:46:50
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameD...
CVE-2026-92583
- EPSS 0.24%
- Veröffentlicht 16.09.2026 21:46:50
- Zuletzt bearbeitet 22.09.2026 20:43:58
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent request...
CVE-2026-92581
- EPSS 0.17%
- Veröffentlicht 16.09.2026 21:46:49
- Zuletzt bearbeitet 22.09.2026 20:43:58
In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters...
CVE-2026-92580
- EPSS 1.11%
- Veröffentlicht 16.09.2026 21:46:48
- Zuletzt bearbeitet 22.09.2026 20:43:58
In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a ...
CVE-2026-92578
- EPSS 0.33%
- Veröffentlicht 16.09.2026 21:46:47
- Zuletzt bearbeitet 22.09.2026 20:43:58
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain...
CVE-2026-92579
- EPSS 0.16%
- Veröffentlicht 16.09.2026 21:46:47
- Zuletzt bearbeitet 22.09.2026 20:43:58
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login....
CVE-2026-92577
- EPSS 0.26%
- Veröffentlicht 16.09.2026 21:46:46
- Zuletzt bearbeitet 22.09.2026 20:43:58
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public ...
CVE-2026-91967
- EPSS 0.33%
- Veröffentlicht 15.09.2026 15:18:19
- Zuletzt bearbeitet 17.09.2026 16:18:31
AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store atta...
CVE-2026-91965
- EPSS 0.41%
- Veröffentlicht 15.09.2026 15:18:18
- Zuletzt bearbeitet 16.09.2026 19:49:18
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles...
CVE-2026-91966
- EPSS 0.38%
- Veröffentlicht 15.09.2026 15:18:18
- Zuletzt bearbeitet 20.09.2026 01:16:34
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbi...