Wwbn

Avideo

345 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 16.09.2026 21:46:50
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameD...

  • EPSS 0.24%
  • Veröffentlicht 16.09.2026 21:46:50
  • Zuletzt bearbeitet 22.09.2026 20:43:58

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent request...

  • EPSS 0.17%
  • Veröffentlicht 16.09.2026 21:46:49
  • Zuletzt bearbeitet 22.09.2026 20:43:58

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters...

  • EPSS 1.11%
  • Veröffentlicht 16.09.2026 21:46:48
  • Zuletzt bearbeitet 22.09.2026 20:43:58

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a ...

  • EPSS 0.33%
  • Veröffentlicht 16.09.2026 21:46:47
  • Zuletzt bearbeitet 22.09.2026 20:43:58

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain...

  • EPSS 0.16%
  • Veröffentlicht 16.09.2026 21:46:47
  • Zuletzt bearbeitet 22.09.2026 20:43:58

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login....

  • EPSS 0.26%
  • Veröffentlicht 16.09.2026 21:46:46
  • Zuletzt bearbeitet 22.09.2026 20:43:58

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public ...

  • EPSS 0.33%
  • Veröffentlicht 15.09.2026 15:18:19
  • Zuletzt bearbeitet 17.09.2026 16:18:31

AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store atta...

  • EPSS 0.41%
  • Veröffentlicht 15.09.2026 15:18:18
  • Zuletzt bearbeitet 16.09.2026 19:49:18

WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles...

  • EPSS 0.38%
  • Veröffentlicht 15.09.2026 15:18:18
  • Zuletzt bearbeitet 20.09.2026 01:16:34

AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbi...