CVE-2026-40926
- EPSS 0.17%
- Veröffentlicht 21.04.2026 22:12:28
- Zuletzt bearbeitet 23.04.2026 15:48:02
WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only a role check...
CVE-2026-40925
- EPSS 0.17%
- Veröffentlicht 21.04.2026 19:58:29
- Zuletzt bearbeitet 24.04.2026 16:46:18
WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST` but protects the endpoint only with `User::isAdmi...
- EPSS 0.65%
- Veröffentlicht 21.04.2026 19:55:37
- Zuletzt bearbeitet 27.04.2026 15:12:57
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without sanitizing the `msg` or `callback` fields. On the client ...
CVE-2026-40909
- EPSS 0.66%
- Veröffentlicht 21.04.2026 19:54:07
- Zuletzt bearbeitet 23.04.2026 18:55:49
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['c...
CVE-2026-40908
- EPSS 0.25%
- Veröffentlicht 21.04.2026 19:52:34
- Zuletzt bearbeitet 23.04.2026 19:09:57
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enab...
CVE-2026-40907
- EPSS 0.27%
- Veröffentlicht 21.04.2026 19:50:10
- Zuletzt bearbeitet 23.04.2026 19:12:33
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming...
CVE-2026-39370
- EPSS 0.21%
- Veröffentlicht 07.04.2026 19:26:27
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions such as .mp4, .mp3, .zip, .jpg, .png, .gif, and .webm...
CVE-2026-39369
- EPSS 0.41%
- Veröffentlicht 07.04.2026 19:24:33
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos/... URLs, bypass traversal scrubbing, and expose s...
CVE-2026-39368
- EPSS 0.21%
- Veröffentlicht 07.04.2026 19:23:29
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamer...
CVE-2026-39367
- EPSS 0.2%
- Veröffentlicht 07.04.2026 19:22:07
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A use...