CVE-2026-89254
- EPSS 0.28%
- Veröffentlicht 11.09.2026 11:15:31
- Zuletzt bearbeitet 11.09.2026 21:17:57
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scr...
CVE-2026-89252
- EPSS 0.19%
- Veröffentlicht 11.09.2026 11:15:30
- Zuletzt bearbeitet 15.09.2026 17:17:35
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS...
CVE-2026-89253
- EPSS 0.35%
- Veröffentlicht 11.09.2026 11:15:30
- Zuletzt bearbeitet 11.09.2026 15:21:12
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it onl...
CVE-2026-89251
- EPSS 0.15%
- Veröffentlicht 11.09.2026 11:15:29
- Zuletzt bearbeitet 11.09.2026 19:17:47
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. At...
CVE-2026-89250
- EPSS 0.38%
- Veröffentlicht 11.09.2026 11:15:28
- Zuletzt bearbeitet 11.09.2026 15:21:12
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoi...
CVE-2026-89248
- EPSS 0.38%
- Veröffentlicht 11.09.2026 11:15:27
- Zuletzt bearbeitet 11.09.2026 15:21:12
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.jso...
CVE-2026-89249
- EPSS 0.28%
- Veröffentlicht 11.09.2026 11:15:27
- Zuletzt bearbeitet 11.09.2026 21:17:57
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.i...
CVE-2026-89247
- EPSS 0.22%
- Veröffentlicht 11.09.2026 11:15:26
- Zuletzt bearbeitet 15.09.2026 17:17:34
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emits Content-...
CVE-2026-89245
- EPSS 0.15%
- Veröffentlicht 11.09.2026 11:15:25
- Zuletzt bearbeitet 11.09.2026 15:21:12
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can craft a maliciou...
CVE-2026-89246
- EPSS 0.18%
- Veröffentlicht 11.09.2026 11:15:25
- Zuletzt bearbeitet 11.09.2026 19:17:47
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated users can in...