CVE-2026-86718
- EPSS 0.18%
- Veröffentlicht 08.09.2026 15:13:52
- Zuletzt bearbeitet 08.09.2026 19:53:13
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET reques...
CVE-2026-86190
- EPSS 0.27%
- Veröffentlicht 05.09.2026 12:09:05
- Zuletzt bearbeitet 08.09.2026 20:05:53
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is pro...
CVE-2026-86188
- EPSS 0.25%
- Veröffentlicht 05.09.2026 12:09:04
- Zuletzt bearbeitet 08.09.2026 20:05:53
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket mes...
CVE-2026-86189
- EPSS 0.41%
- Veröffentlicht 05.09.2026 12:09:04
- Zuletzt bearbeitet 18.09.2026 18:17:18
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any ...
CVE-2026-86187
- EPSS 0.22%
- Veröffentlicht 05.09.2026 12:09:03
- Zuletzt bearbeitet 10.09.2026 16:18:01
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-f...
CVE-2026-86186
- EPSS 0.18%
- Veröffentlicht 05.09.2026 12:09:02
- Zuletzt bearbeitet 08.09.2026 20:05:53
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate l...
CVE-2026-85577
- EPSS 0.26%
- Veröffentlicht 04.09.2026 11:29:47
- Zuletzt bearbeitet 08.09.2026 20:05:53
AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious UR...
CVE-2026-85164
- EPSS 0.24%
- Veröffentlicht 03.09.2026 11:22:15
- Zuletzt bearbeitet 08.09.2026 20:18:59
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply inter...
CVE-2026-85163
- EPSS 0.21%
- Veröffentlicht 03.09.2026 11:22:14
- Zuletzt bearbeitet 08.09.2026 20:18:59
AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during vide...
CVE-2026-85161
- EPSS 0.1%
- Veröffentlicht 03.09.2026 11:22:13
- Zuletzt bearbeitet 08.09.2026 20:18:59
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster a...