CVE-2026-34613
- EPSS 0.02%
- Veröffentlicht 31.03.2026 20:45:50
- Zuletzt bearbeitet 01.04.2026 20:30:11
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session but does not ...
CVE-2026-34611
- EPSS 0.02%
- Veröffentlicht 31.03.2026 20:42:37
- Zuletzt bearbeitet 01.04.2026 20:33:55
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session...
CVE-2026-34396
- EPSS 0.03%
- Veröffentlicht 31.03.2026 20:40:43
- Zuletzt bearbeitet 01.04.2026 20:34:13
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms without applying htmlspecialchars() or any other output encoding. The jsonToFormElements() function in ...
CVE-2026-34394
- EPSS 0.02%
- Veröffentlicht 31.03.2026 20:39:45
- Zuletzt bearbeitet 01.04.2026 20:38:14
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before processing ...
CVE-2026-34395
- EPSS 0.03%
- Veröffentlicht 31.03.2026 20:38:54
- Zuletzt bearbeitet 01.04.2026 20:35:18
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks ...
CVE-2026-34375
- EPSS 0.04%
- Veröffentlicht 27.03.2026 18:17:32
- Zuletzt bearbeitet 31.03.2026 18:48:56
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any encoding or sanitization. The `...
CVE-2026-34374
- EPSS 0.04%
- Veröffentlicht 27.03.2026 18:16:22
- Zuletzt bearbeitet 31.03.2026 18:49:13
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is c...
CVE-2026-34364
- EPSS 0.01%
- Veröffentlicht 27.03.2026 18:16:05
- Zuletzt bearbeitet 14.04.2026 01:22:38
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access controls on categories. In the default request pat...
CVE-2026-34368
- EPSS 0.03%
- Veröffentlicht 27.03.2026 18:16:05
- Zuletzt bearbeitet 31.03.2026 16:25:04
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sender's wallet ...
CVE-2026-34369
- EPSS 0.06%
- Veröffentlicht 27.03.2026 18:13:23
- Zuletzt bearbeitet 31.03.2026 18:50:13
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos...