CVE-2026-90543
- EPSS 0.28%
- Veröffentlicht 12.09.2026 12:08:49
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg` parameters ...
CVE-2026-90541
- EPSS 0.24%
- Veröffentlicht 12.09.2026 12:08:48
- Zuletzt bearbeitet 19.09.2026 15:17:07
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the en...
CVE-2026-90540
- EPSS 0.16%
- Veröffentlicht 12.09.2026 12:08:47
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos they cannot w...
CVE-2026-90538
- EPSS 0.21%
- Veröffentlicht 12.09.2026 12:08:46
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. ...
CVE-2026-90539
- EPSS 0.24%
- Veröffentlicht 12.09.2026 12:08:46
- Zuletzt bearbeitet 14.09.2026 21:07:11
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submittin...
CVE-2026-90537
- EPSS 0.21%
- Veröffentlicht 12.09.2026 12:08:45
- Zuletzt bearbeitet 15.09.2026 17:17:37
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide da...
CVE-2026-90536
- EPSS 0.24%
- Veröffentlicht 12.09.2026 12:08:44
- Zuletzt bearbeitet 21.09.2026 17:19:15
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API w...
CVE-2026-89257
- EPSS 0.18%
- Veröffentlicht 11.09.2026 11:15:33
- Zuletzt bearbeitet 15.09.2026 17:17:35
AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the attacker-supp...
CVE-2026-89255
- EPSS 0.35%
- Veröffentlicht 11.09.2026 11:15:32
- Zuletzt bearbeitet 11.09.2026 15:21:12
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inj...
CVE-2026-89256
- EPSS 0.32%
- Veröffentlicht 11.09.2026 11:15:32
- Zuletzt bearbeitet 11.09.2026 20:19:23
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can in...