Wwbn

Avideo

206 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 27.03.2026 18:16:05
  • Zuletzt bearbeitet 31.03.2026 16:25:04

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sender's wallet ...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 27.03.2026 18:13:23
  • Zuletzt bearbeitet 31.03.2026 18:50:13

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 27.03.2026 16:42:28
  • Zuletzt bearbeitet 31.03.2026 16:32:59

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despit...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 27.03.2026 16:39:05
  • Zuletzt bearbeitet 31.03.2026 16:36:54

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary `live_...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 27.03.2026 16:32:35
  • Zuletzt bearbeitet 31.03.2026 16:41:04

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast schedules ...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 27.03.2026 16:30:17
  • Zuletzt bearbeitet 31.03.2026 16:43:15

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is ...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 27.03.2026 16:13:51
  • Zuletzt bearbeitet 31.03.2026 16:46:25

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` constructs a SQL SELECT query by directly interpolating both `$clean_title` and `$id` into the query str...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 27.03.2026 16:12:36
  • Zuletzt bearbeitet 31.03.2026 16:48:14

WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using a prepared statement placeholder (`?`) for `users_id` but directly concatenates `$this->vid...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 27.03.2026 14:31:06
  • Zuletzt bearbeitet 31.03.2026 18:48:32

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP ranges before fetching, but `url_get_contents()` follows HTTP redirects without re-validating the redirec...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 27.03.2026 14:29:53
  • Zuletzt bearbeitet 31.03.2026 18:45:13

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endpoint loads AI response objects using an attacker-controlled `$_REQUEST['id']` parameter without validating that the AI response be...