Wwbn

Avideo

220 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 15.07.2026 21:13:06
  • Zuletzt bearbeitet 16.07.2026 14:16:52

WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data API into the homepage gallery ...

  • EPSS 0.18%
  • Veröffentlicht 15.07.2026 21:04:26
  • Zuletzt bearbeitet 17.07.2026 13:18:56

WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenated directly into the href attri...

  • EPSS 0.33%
  • Veröffentlicht 15.07.2026 20:57:21
  • Zuletzt bearbeitet 18.07.2026 03:16:36

WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML fro...

  • EPSS 0.21%
  • Veröffentlicht 15.07.2026 20:47:45
  • Zuletzt bearbeitet 16.07.2026 14:16:50

WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during accou...

  • EPSS 0.26%
  • Veröffentlicht 20.06.2026 18:27:13
  • Zuletzt bearbeitet 22.06.2026 19:17:30

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped ...

  • EPSS 0.14%
  • Veröffentlicht 29.05.2026 13:14:49
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, witho...

  • EPSS 0.32%
  • Veröffentlicht 29.05.2026 13:14:02
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by string concatenation, single-qu...

  • EPSS 0.11%
  • Veröffentlicht 29.05.2026 13:13:08
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA value=false, calls LoginControl::setUser2FA(User::getI...

  • EPSS 0.14%
  • Veröffentlicht 29.05.2026 13:11:37
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS pinning via CURLOPT_RESOLVE, opening DNS-rebinding ...

  • EPSS 0.19%
  • Veröffentlicht 29.05.2026 13:07:19
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenti...