CVE-2026-33500
- EPSS 0.03%
- Veröffentlicht 23.03.2026 16:24:52
- Zuletzt bearbeitet 24.03.2026 18:11:11
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `<a>` and `<img>` tags in comments, but ex...
CVE-2026-33499
- EPSS 0.01%
- Veröffentlicht 23.03.2026 16:11:57
- Zuletzt bearbeitet 24.03.2026 18:11:56
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` parameter directly into an HTML `<input>` tag's attributes...
CVE-2026-33493
- EPSS 0.08%
- Veröffentlicht 23.03.2026 15:52:33
- Zuletzt bearbeitet 24.03.2026 18:17:24
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `objects/listF...
CVE-2026-33492
- EPSS 0.07%
- Veröffentlicht 23.03.2026 15:25:27
- Zuletzt bearbeitet 24.03.2026 17:47:58
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration b...
CVE-2026-33488
- EPSS 0.02%
- Veröffentlicht 23.03.2026 15:23:01
- Zuletzt bearbeitet 24.03.2026 17:49:58
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who ob...
CVE-2026-33485
- EPSS 0.21%
- Veröffentlicht 23.03.2026 14:14:15
- Zuletzt bearbeitet 24.03.2026 18:35:45
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated direc...
CVE-2026-33483
- EPSS 0.4%
- Veröffentlicht 23.03.2026 14:12:05
- Zuletzt bearbeitet 24.03.2026 18:36:55
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An unauthentic...
CVE-2026-33482
- EPSS 0.09%
- Veröffentlicht 23.03.2026 14:10:10
- Zuletzt bearbeitet 24.03.2026 18:41:00
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous ...
CVE-2026-33480
- EPSS 0.04%
- Veröffentlicht 23.03.2026 14:08:49
- Zuletzt bearbeitet 24.03.2026 18:46:11
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`). The unauthenticated `plugin/LiveLinks/proxy.php` endpoin...
CVE-2026-33479
- EPSS 0.14%
- Veröffentlicht 23.03.2026 14:05:55
- Zuletzt bearbeitet 24.03.2026 18:48:38
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user input from `$_REQUEST['sections']` array values directly into PHP's `eval()` function. While...