Wwbn

Avideo

206 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 06.04.2026 21:45:01
  • Zuletzt bearbeitet 14.04.2026 19:57:27

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an AJAX pollin...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 06.04.2026 19:09:45
  • Zuletzt bearbeitet 14.04.2026 19:57:50

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based securi...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 06.04.2026 19:06:46
  • Zuletzt bearbeitet 15.04.2026 18:42:29

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-bas...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 06.04.2026 19:05:49
  • Zuletzt bearbeitet 23.04.2026 15:31:52

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts use...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 31.03.2026 20:57:14
  • Zuletzt bearbeitet 01.04.2026 18:43:31

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page v...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 31.03.2026 20:56:16
  • Zuletzt bearbeitet 01.04.2026 18:42:45

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other output encodin...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 31.03.2026 20:55:09
  • Zuletzt bearbeitet 01.04.2026 18:42:05

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active" (a). This...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 31.03.2026 20:53:51
  • Zuletzt bearbeitet 01.04.2026 18:45:32

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 31.03.2026 20:52:45
  • Zuletzt bearbeitet 01.04.2026 18:40:28

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively f...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 31.03.2026 20:51:51
  • Zuletzt bearbeitet 01.04.2026 18:38:07

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php bo...