CVE-2026-89244
- EPSS 0.16%
- Veröffentlicht 11.09.2026 11:15:24
- Zuletzt bearbeitet 11.09.2026 21:17:57
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href attribute wi...
CVE-2026-89242
- EPSS 0.17%
- Veröffentlicht 11.09.2026 11:15:23
- Zuletzt bearbeitet 15.09.2026 17:17:34
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can...
CVE-2026-89243
- EPSS 0.36%
- Veröffentlicht 11.09.2026 11:15:23
- Zuletzt bearbeitet 11.09.2026 15:21:12
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inj...
CVE-2026-89241
- EPSS 0.2%
- Veröffentlicht 11.09.2026 11:15:22
- Zuletzt bearbeitet 11.09.2026 20:19:23
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malici...
CVE-2026-89240
- EPSS 0.24%
- Veröffentlicht 11.09.2026 11:15:21
- Zuletzt bearbeitet 11.09.2026 15:21:12
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $...
CVE-2026-89148
- EPSS 0.15%
- Veröffentlicht 11.09.2026 11:15:20
- Zuletzt bearbeitet 11.09.2026 15:21:12
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does n...
CVE-2026-89239
- EPSS 0.16%
- Veröffentlicht 11.09.2026 11:15:20
- Zuletzt bearbeitet 11.09.2026 21:17:56
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding. Attackers c...
CVE-2026-88875
- EPSS 0.22%
- Veröffentlicht 10.09.2026 13:05:28
- Zuletzt bearbeitet 18.09.2026 18:17:37
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and API::get_api_v...
CVE-2026-88876
- EPSS 0.32%
- Veröffentlicht 10.09.2026 13:05:28
- Zuletzt bearbeitet 15.09.2026 15:17:25
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() wit...
CVE-2026-88874
- EPSS 0.51%
- Veröffentlicht 10.09.2026 13:05:27
- Zuletzt bearbeitet 10.09.2026 16:18:11
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected tr...