Wwbn

Avideo

345 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 11.09.2026 11:15:24
  • Zuletzt bearbeitet 11.09.2026 21:17:57

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href attribute wi...

  • EPSS 0.17%
  • Veröffentlicht 11.09.2026 11:15:23
  • Zuletzt bearbeitet 15.09.2026 17:17:34

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can...

  • EPSS 0.36%
  • Veröffentlicht 11.09.2026 11:15:23
  • Zuletzt bearbeitet 11.09.2026 15:21:12

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inj...

  • EPSS 0.2%
  • Veröffentlicht 11.09.2026 11:15:22
  • Zuletzt bearbeitet 11.09.2026 20:19:23

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malici...

  • EPSS 0.24%
  • Veröffentlicht 11.09.2026 11:15:21
  • Zuletzt bearbeitet 11.09.2026 15:21:12

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $...

  • EPSS 0.15%
  • Veröffentlicht 11.09.2026 11:15:20
  • Zuletzt bearbeitet 11.09.2026 15:21:12

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does n...

  • EPSS 0.16%
  • Veröffentlicht 11.09.2026 11:15:20
  • Zuletzt bearbeitet 11.09.2026 21:17:56

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding. Attackers c...

  • EPSS 0.22%
  • Veröffentlicht 10.09.2026 13:05:28
  • Zuletzt bearbeitet 18.09.2026 18:17:37

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and API::get_api_v...

  • EPSS 0.32%
  • Veröffentlicht 10.09.2026 13:05:28
  • Zuletzt bearbeitet 15.09.2026 15:17:25

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() wit...

  • EPSS 0.51%
  • Veröffentlicht 10.09.2026 13:05:27
  • Zuletzt bearbeitet 10.09.2026 16:18:11

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected tr...