Wwbn

Avideo

220 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.17%
  • Veröffentlicht 21.04.2026 22:12:28
  • Zuletzt bearbeitet 23.04.2026 15:48:02

WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 21.04.2026 19:58:29
  • Zuletzt bearbeitet 24.04.2026 16:46:18

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST` but protects the endpoint only with `User::isAdmi...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 21.04.2026 19:55:37
  • Zuletzt bearbeitet 27.04.2026 15:12:57

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without sanitizing the `msg` or `callback` fields. On the client ...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 21.04.2026 19:54:07
  • Zuletzt bearbeitet 23.04.2026 18:55:49

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['c...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 21.04.2026 19:52:34
  • Zuletzt bearbeitet 23.04.2026 19:09:57

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enab...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 21.04.2026 19:50:10
  • Zuletzt bearbeitet 23.04.2026 19:12:33

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming...

  • EPSS 0.21%
  • Veröffentlicht 07.04.2026 19:26:27
  • Zuletzt bearbeitet 24.07.2026 21:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm...

  • EPSS 0.41%
  • Veröffentlicht 07.04.2026 19:24:33
  • Zuletzt bearbeitet 24.07.2026 21:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose s...

  • EPSS 0.21%
  • Veröffentlicht 07.04.2026 19:23:29
  • Zuletzt bearbeitet 24.07.2026 21:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamer...

  • EPSS 0.2%
  • Veröffentlicht 07.04.2026 19:22:07
  • Zuletzt bearbeitet 24.07.2026 21:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A use...