Wwbn

Avideo

220 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.47%
  • Veröffentlicht 29.05.2026 13:05:02
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line execution as part of a database migration. An authenticate...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 29.05.2026 13:03:01
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that the PHP user can open — including private user-profile photos that the application's normal ser...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 29.05.2026 13:00:37
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_description as raw HTML in the Gallery view. A user who can create or edit categories can store JavaScri...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 29.05.2026 12:59:30
  • Zuletzt bearbeitet 21.07.2026 12:10:00

WWBN AVideo is an open source video platform. In 29.0 and earlier, plugin/AuthorizeNet/processPayment.json.php credits the logged-in user's wallet based only on the attacker-controlled amount POST parameter. The endpoint contains a TODO for real Auth...

  • EPSS 0.26%
  • Veröffentlicht 11.05.2026 20:45:21
  • Zuletzt bearbeitet 15.05.2026 19:16:58

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f...

  • EPSS 0.35%
  • Veröffentlicht 11.05.2026 20:44:08
  • Zuletzt bearbeitet 12.05.2026 14:50:18

WWBN AVideo is an open source video platform. In versions up to and including 29.0, two endpoints (plugin/AI/receiveAsync.json.php and objects/EpgParser.php) in AVideo call isSSRFSafeURL() to validate user-supplied URLs, then fetch them using bare fi...

  • EPSS 0.17%
  • Veröffentlicht 11.05.2026 20:41:40
  • Zuletzt bearbeitet 12.05.2026 18:17:28

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/PayPalYPT/agreementCancel.json.php cancels a PayPal billing agreement using an attacker-supplied agreement parameter without verifying that the authenticated u...

  • EPSS 0.18%
  • Veröffentlicht 11.05.2026 20:40:53
  • Zuletzt bearbeitet 13.05.2026 16:16:52

WWBN AVideo is an open source video platform. In versions up to and including 29.0, the unauthenticated plugin/Scheduler/downloadICS.php endpoint passes attacker-controlled title, description, and joinURL parameters into Scheduler::downloadICS(), whi...

  • EPSS 0.27%
  • Veröffentlicht 11.05.2026 20:38:06
  • Zuletzt bearbeitet 12.05.2026 14:50:18

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/users.json.php exposes two unauthenticated paths that disclose the full set of registered user accounts. The isCompany request parameter causes the handler to...

  • EPSS 0.23%
  • Veröffentlicht 11.05.2026 20:37:15
  • Zuletzt bearbeitet 12.05.2026 14:50:18

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/sendEmail.json.php exposes two branches depending on whether contactForm=1 is submitted. When the parameter is omitted, the endpoint sets $sendTo to an attack...