CVE-2026-90552
- EPSS 0.21%
- Veröffentlicht 12.09.2026 12:08:56
- Zuletzt bearbeitet 15.09.2026 18:19:36
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private p...
CVE-2026-90551
- EPSS 0.24%
- Veröffentlicht 12.09.2026 12:08:55
- Zuletzt bearbeitet 21.09.2026 17:19:15
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authent...
CVE-2026-90550
- EPSS 0.24%
- Veröffentlicht 12.09.2026 12:08:54
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint with a video I...
CVE-2026-90548
- EPSS 0.23%
- Veröffentlicht 12.09.2026 12:08:53
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of pas...
CVE-2026-90549
- EPSS 0.21%
- Veröffentlicht 12.09.2026 12:08:53
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attacke...
CVE-2026-90547
- EPSS 0.24%
- Veröffentlicht 12.09.2026 12:08:52
- Zuletzt bearbeitet 15.09.2026 18:19:36
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Att...
CVE-2026-90545
- EPSS 0.18%
- Veröffentlicht 12.09.2026 12:08:51
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. At...
CVE-2026-90546
- EPSS 0.22%
- Veröffentlicht 12.09.2026 12:08:51
- Zuletzt bearbeitet 21.09.2026 17:19:15
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can su...
CVE-2026-90544
- EPSS 0.16%
- Veröffentlicht 12.09.2026 12:08:50
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-tim...
CVE-2026-90542
- EPSS 0.14%
- Veröffentlicht 12.09.2026 12:08:49
- Zuletzt bearbeitet 15.09.2026 18:19:36
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private l...