CVE-2026-40908
- EPSS 0.25%
- Veröffentlicht 21.04.2026 19:52:34
- Zuletzt bearbeitet 23.04.2026 19:09:57
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enab...
CVE-2026-40907
- EPSS 0.27%
- Veröffentlicht 21.04.2026 19:50:10
- Zuletzt bearbeitet 23.04.2026 19:12:33
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming...
CVE-2026-39370
- EPSS 0.21%
- Veröffentlicht 07.04.2026 19:26:27
- Zuletzt bearbeitet 22.04.2026 18:50:11
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm...
CVE-2026-39369
- EPSS 0.41%
- Veröffentlicht 07.04.2026 19:24:33
- Zuletzt bearbeitet 22.04.2026 18:50:33
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose s...
CVE-2026-39368
- EPSS 0.21%
- Veröffentlicht 07.04.2026 19:23:29
- Zuletzt bearbeitet 22.04.2026 18:50:53
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamer...
CVE-2026-39367
- EPSS 0.2%
- Veröffentlicht 07.04.2026 19:22:07
- Zuletzt bearbeitet 22.04.2026 18:51:19
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A use...
CVE-2026-39366
- EPSS 0.17%
- Veröffentlicht 07.04.2026 19:21:12
- Zuletzt bearbeitet 22.04.2026 18:51:32
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate...
CVE-2026-35452
- EPSS 0.37%
- Veröffentlicht 06.04.2026 21:47:45
- Zuletzt bearbeitet 14.04.2026 15:37:41
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces Use...
CVE-2026-35450
- EPSS 0.37%
- Veröffentlicht 06.04.2026 21:46:54
- Zuletzt bearbeitet 14.04.2026 15:37:29
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg manag...
CVE-2026-35449
- EPSS 0.33%
- Veröffentlicht 06.04.2026 21:46:07
- Zuletzt bearbeitet 23.04.2026 15:31:39
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, ...