CVE-2026-34731
- EPSS 0.48%
- Veröffentlicht 31.03.2026 20:50:23
- Zuletzt bearbeitet 01.04.2026 18:37:42
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthenticated users to terminate any active live stream. The endpoint processes RTMP callback events to mark...
CVE-2026-34716
- EPSS 0.28%
- Veröffentlicht 31.03.2026 20:49:21
- Zuletzt bearbeitet 01.04.2026 18:37:08
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the heading parame...
CVE-2026-34613
- EPSS 0.2%
- Veröffentlicht 31.03.2026 20:45:50
- Zuletzt bearbeitet 01.04.2026 20:30:11
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session but does not ...
CVE-2026-34611
- EPSS 0.16%
- Veröffentlicht 31.03.2026 20:42:37
- Zuletzt bearbeitet 01.04.2026 20:33:55
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session...
CVE-2026-34396
- EPSS 0.22%
- Veröffentlicht 31.03.2026 20:40:43
- Zuletzt bearbeitet 01.04.2026 20:34:13
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms without applying htmlspecialchars() or any other output encoding. The jsonToFormElements() function in ...
CVE-2026-34394
- EPSS 0.23%
- Veröffentlicht 31.03.2026 20:39:45
- Zuletzt bearbeitet 01.04.2026 20:38:14
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before processing ...
CVE-2026-34395
- EPSS 0.32%
- Veröffentlicht 31.03.2026 20:38:54
- Zuletzt bearbeitet 01.04.2026 20:35:18
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks ...
CVE-2026-34375
- EPSS 0.3%
- Veröffentlicht 27.03.2026 18:17:32
- Zuletzt bearbeitet 31.03.2026 18:48:56
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any encoding or sanitization. The `...
CVE-2026-34374
- EPSS 0.34%
- Veröffentlicht 27.03.2026 18:16:22
- Zuletzt bearbeitet 31.03.2026 18:49:13
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is c...
CVE-2026-34364
- EPSS 0.32%
- Veröffentlicht 27.03.2026 18:16:05
- Zuletzt bearbeitet 14.04.2026 01:22:38
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access controls on categories. In the default request pat...