CVE-2026-88873
- EPSS 0.14%
- Veröffentlicht 10.09.2026 13:05:26
- Zuletzt bearbeitet 10.09.2026 15:17:57
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests without CSRF ...
CVE-2026-88871
- EPSS 0.14%
- Veröffentlicht 10.09.2026 13:05:25
- Zuletzt bearbeitet 15.09.2026 15:17:25
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script reads users_i...
CVE-2026-88872
- EPSS 0.17%
- Veröffentlicht 10.09.2026 13:05:25
- Zuletzt bearbeitet 10.09.2026 15:17:57
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET reque...
CVE-2026-88870
- EPSS 0.13%
- Veröffentlicht 10.09.2026 13:05:24
- Zuletzt bearbeitet 18.09.2026 18:17:36
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages with image tags ...
CVE-2026-88868
- EPSS 0.26%
- Veröffentlicht 10.09.2026 13:05:23
- Zuletzt bearbeitet 10.09.2026 15:17:57
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can injec...
CVE-2026-88869
- EPSS 0.48%
- Veröffentlicht 10.09.2026 13:05:23
- Zuletzt bearbeitet 10.09.2026 16:18:10
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can in...
CVE-2026-88867
- EPSS 0.32%
- Veröffentlicht 10.09.2026 13:05:22
- Zuletzt bearbeitet 10.09.2026 15:17:57
WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Category::setName...
CVE-2026-88865
- EPSS 0.26%
- Veröffentlicht 10.09.2026 13:05:21
- Zuletzt bearbeitet 18.09.2026 18:17:36
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the tok...
CVE-2026-88866
- EPSS 0.31%
- Veröffentlicht 10.09.2026 13:05:21
- Zuletzt bearbeitet 15.09.2026 15:17:25
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any vali...
CVE-2026-86729
- EPSS 0.22%
- Veröffentlicht 08.09.2026 15:14:00
- Zuletzt bearbeitet 10.09.2026 16:18:03
WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRate...