Wwbn

Avideo

220 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Veröffentlicht 31.03.2026 20:55:09
  • Zuletzt bearbeitet 24.07.2026 21:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active" (a). This...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 31.03.2026 20:53:51
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 31.03.2026 20:52:45
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively f...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 31.03.2026 20:51:51
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php bo...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 31.03.2026 20:50:23
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthenticated users to terminate any active live stream. The endpoint processes RTMP callback events to mark...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 31.03.2026 20:49:21
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the heading parame...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 31.03.2026 20:45:50
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session but does not ...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 31.03.2026 20:42:37
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 31.03.2026 20:40:43
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms without applying htmlspecialchars() or any other output encoding. The jsonToFormElements() function in ...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 31.03.2026 20:39:45
  • Zuletzt bearbeitet 24.07.2026 20:10:00

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before processing ...