Wwbn

Avideo

345 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 08.09.2026 15:13:52
  • Zuletzt bearbeitet 08.09.2026 19:53:13

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET reques...

  • EPSS 0.27%
  • Veröffentlicht 05.09.2026 12:09:05
  • Zuletzt bearbeitet 08.09.2026 20:05:53

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is pro...

  • EPSS 0.25%
  • Veröffentlicht 05.09.2026 12:09:04
  • Zuletzt bearbeitet 08.09.2026 20:05:53

AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket mes...

  • EPSS 0.41%
  • Veröffentlicht 05.09.2026 12:09:04
  • Zuletzt bearbeitet 18.09.2026 18:17:18

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any ...

  • EPSS 0.22%
  • Veröffentlicht 05.09.2026 12:09:03
  • Zuletzt bearbeitet 10.09.2026 16:18:01

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-f...

  • EPSS 0.18%
  • Veröffentlicht 05.09.2026 12:09:02
  • Zuletzt bearbeitet 08.09.2026 20:05:53

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate l...

  • EPSS 0.26%
  • Veröffentlicht 04.09.2026 11:29:47
  • Zuletzt bearbeitet 08.09.2026 20:05:53

AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScript by closing the script tag with </script>. Attackers can craft a malicious UR...

  • EPSS 0.24%
  • Veröffentlicht 03.09.2026 11:22:15
  • Zuletzt bearbeitet 08.09.2026 20:18:59

WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply inter...

  • EPSS 0.21%
  • Veröffentlicht 03.09.2026 11:22:14
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker can supply an internal URL via the epg_link parameter during vide...

  • EPSS 0.1%
  • Veröffentlicht 03.09.2026 11:22:13
  • Zuletzt bearbeitet 08.09.2026 20:18:59

AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to delete authenticated victims' live poster a...