CVE-2026-43875
- EPSS 0.29%
- Veröffentlicht 11.05.2026 20:32:05
- Zuletzt bearbeitet 12.05.2026 14:50:18
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=<email>&pass=<HASH> where <HASH> is the victim's stor...
CVE-2026-43873
- EPSS 0.26%
- Veröffentlicht 11.05.2026 20:31:06
- Zuletzt bearbeitet 12.05.2026 14:50:18
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($global['systemRootPath'] . $global['salt'])) into th...
CVE-2026-43874
- EPSS 0.24%
- Veröffentlicht 11.05.2026 20:29:59
- Zuletzt bearbeitet 12.05.2026 14:50:18
WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML eval sink (from CVE-2026-40911) only strips the payload when it sits under $json['msg'], but the relay...
CVE-2026-41304
- EPSS 2.22%
- Veröffentlicht 21.04.2026 23:07:48
- Zuletzt bearbeitet 24.04.2026 15:11:04
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is di...
CVE-2026-41064
- EPSS 0.34%
- Veröffentlicht 21.04.2026 23:04:32
- Zuletzt bearbeitet 24.04.2026 15:10:50
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation ...
CVE-2026-41063
- EPSS 0.22%
- Veröffentlicht 21.04.2026 22:59:52
- Zuletzt bearbeitet 24.04.2026 15:08:58
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javas...
CVE-2026-41062
- EPSS 0.72%
- Veröffentlicht 21.04.2026 22:57:26
- Zuletzt bearbeitet 24.04.2026 15:08:46
WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks the URL path component (via `parse_url($url, PHP_URL_PAT...
CVE-2026-41061
- EPSS 0.17%
- Veröffentlicht 21.04.2026 22:49:40
- Zuletzt bearbeitet 24.04.2026 15:08:34
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor, allowing arbitrary HTML/JavaScript to be appended ...
CVE-2026-41060
- EPSS 0.3%
- Veröffentlicht 21.04.2026 22:44:44
- Zuletzt bearbeitet 24.04.2026 15:08:25
WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows any URL whose hostname matches `webSiteRootURL` to b...
CVE-2026-41058
- EPSS 0.47%
- Veröffentlicht 21.04.2026 22:43:17
- Zuletzt bearbeitet 24.04.2026 15:07:57
WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in the G...