CVE-2026-34395
- EPSS 0.32%
- Veröffentlicht 31.03.2026 20:38:54
- Zuletzt bearbeitet 24.07.2026 20:10:00
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks ...
CVE-2026-34375
- EPSS 0.3%
- Veröffentlicht 27.03.2026 18:17:32
- Zuletzt bearbeitet 31.03.2026 18:48:56
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any encoding or sanitization. The `...
CVE-2026-34374
- EPSS 0.34%
- Veröffentlicht 27.03.2026 18:16:22
- Zuletzt bearbeitet 31.03.2026 18:49:13
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is c...
CVE-2026-34364
- EPSS 0.32%
- Veröffentlicht 27.03.2026 18:16:05
- Zuletzt bearbeitet 14.04.2026 01:22:38
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access controls on categories. In the default request pat...
CVE-2026-34368
- EPSS 0.23%
- Veröffentlicht 27.03.2026 18:16:05
- Zuletzt bearbeitet 31.03.2026 16:25:04
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sender's wallet ...
CVE-2026-34369
- EPSS 0.38%
- Veröffentlicht 27.03.2026 18:13:23
- Zuletzt bearbeitet 31.03.2026 18:50:13
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos...
CVE-2026-34362
- EPSS 0.25%
- Veröffentlicht 27.03.2026 16:42:28
- Zuletzt bearbeitet 31.03.2026 16:32:59
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despit...
CVE-2026-34247
- EPSS 0.24%
- Veröffentlicht 27.03.2026 16:39:05
- Zuletzt bearbeitet 31.03.2026 16:36:54
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary `live_...
CVE-2026-34245
- EPSS 0.25%
- Veröffentlicht 27.03.2026 16:32:35
- Zuletzt bearbeitet 31.03.2026 16:41:04
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast schedules ...
CVE-2026-33867
- EPSS 0.15%
- Veröffentlicht 27.03.2026 16:30:17
- Zuletzt bearbeitet 31.03.2026 16:43:15
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is ...