Wwbn

Avideo

164 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.05%
  • Veröffentlicht 27.03.2026 14:18:48
  • Zuletzt bearbeitet 31.03.2026 18:38:16

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any authentication or authorization check. Private playl...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 23.03.2026 18:50:33
  • Zuletzt bearbeitet 25.03.2026 19:04:07

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concatenates the `$this->users_id` property directly into an INSERT SQL query without sanitization or parame...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 23.03.2026 18:49:28
  • Zuletzt bearbeitet 25.03.2026 14:56:57

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disable.json.php` use key-based authentication with an empty string default key. When the CDN pl...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 23.03.2026 18:48:24
  • Zuletzt bearbeitet 25.03.2026 14:57:45

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a web-accessible temporary directory using the original URL'...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 23.03.2026 18:46:47
  • Zuletzt bearbeitet 25.03.2026 15:05:05

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 23.03.2026 18:45:25
  • Zuletzt bearbeitet 25.03.2026 15:06:07

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client's IP address. An attacker can spoof their IP add...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 23.03.2026 18:43:59
  • Zuletzt bearbeitet 25.03.2026 18:05:21

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allows an unauth...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 23.03.2026 18:42:45
  • Zuletzt bearbeitet 25.03.2026 19:04:36

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no authentication or authorization checks, allowing any unauthenticated attacker to extract ad campaign anal...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 23.03.2026 18:41:13
  • Zuletzt bearbeitet 25.03.2026 18:04:29

WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "about" field allows any registered user to inject arbitrary JavaScript that executes when other users vis...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 23.03.2026 18:39:33
  • Zuletzt bearbeitet 25.03.2026 18:03:12

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a `name` parameter via POST and passes it to `Plugin::getDatabaseFileName()` without any path traversa...