CVE-2026-39366
- EPSS 0.17%
- Veröffentlicht 07.04.2026 19:21:12
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a single legitimate IPN notification to repeatedly inflate...
CVE-2026-35452
- EPSS 0.37%
- Veröffentlicht 06.04.2026 21:47:45
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces Use...
CVE-2026-35450
- EPSS 0.37%
- Veröffentlicht 06.04.2026 21:46:54
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg manag...
CVE-2026-35449
- EPSS 0.33%
- Veröffentlicht 06.04.2026 21:46:07
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, ...
CVE-2026-35448
- EPSS 0.32%
- Veröffentlicht 06.04.2026 21:45:01
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an AJAX pollin...
CVE-2026-35181
- EPSS 0.13%
- Veröffentlicht 06.04.2026 19:09:45
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based securi...
CVE-2026-35180
- EPSS 0.11%
- Veröffentlicht 06.04.2026 19:06:46
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the site customization endpoint at admin/customize_settings_nativeUpdate.json.php lacks CSRF token validation and writes uploaded logo files to disk before the ORM's domain-bas...
CVE-2026-35179
- EPSS 0.22%
- Veröffentlicht 06.04.2026 19:05:49
- Zuletzt bearbeitet 24.07.2026 21:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts use...
CVE-2026-34740
- EPSS 0.32%
- Veröffentlicht 31.03.2026 20:57:14
- Zuletzt bearbeitet 24.07.2026 20:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page v...
CVE-2026-34739
- EPSS 0.22%
- Veröffentlicht 31.03.2026 20:56:16
- Zuletzt bearbeitet 24.07.2026 20:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other output encodin...