CVE-2026-50183
- EPSS 0.16%
- Veröffentlicht 15.07.2026 21:13:06
- Zuletzt bearbeitet 16.07.2026 14:16:52
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data API into the homepage gallery ...
CVE-2026-50182
- EPSS 0.18%
- Veröffentlicht 15.07.2026 21:04:26
- Zuletzt bearbeitet 17.07.2026 13:18:56
WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenated directly into the href attri...
CVE-2026-49279
- EPSS 0.33%
- Veröffentlicht 15.07.2026 20:57:21
- Zuletzt bearbeitet 18.07.2026 03:16:36
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML fro...
CVE-2026-33684
- EPSS 0.21%
- Veröffentlicht 15.07.2026 20:47:45
- Zuletzt bearbeitet 16.07.2026 14:16:50
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during accou...
CVE-2026-56347
- EPSS 0.26%
- Veröffentlicht 20.06.2026 18:27:13
- Zuletzt bearbeitet 22.06.2026 19:17:30
AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped ...
CVE-2026-45580
- EPSS 0.14%
- Veröffentlicht 29.05.2026 13:14:49
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, witho...
CVE-2026-45578
- EPSS 0.32%
- Veröffentlicht 29.05.2026 13:14:02
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-qu...
CVE-2026-45610
- EPSS 0.11%
- Veröffentlicht 29.05.2026 13:13:08
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getI...
CVE-2026-45619
- EPSS 0.14%
- Veröffentlicht 29.05.2026 13:11:37
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS pinning via CURLOPT_RESOLVE, opening DNS-rebinding ...
CVE-2026-45620
- EPSS 0.19%
- Veröffentlicht 29.05.2026 13:07:19
- Zuletzt bearbeitet 21.07.2026 12:10:00
WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenti...