WWBN AVideo
118 known vulnerabilities in WWBN AVideo, 21 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-105089 CVSS 9.3 critical WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script…
- CVE-2026-105086 CVSS 9.3 critical WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by…
- CVE-2026-100630 CVSS 5.1 medium AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an…
- CVE-2026-92915 CVSS 6.9 medium WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php…
- CVE-2026-92914 CVSS 8.6 high AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge…
- CVE-2026-92913 CVSS 9.1 critical AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating…
- CVE-2026-92912 CVSS 8.3 high AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in…
- CVE-2026-92586 CVSS 5.3 medium AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment…
- CVE-2026-92585 CVSS 5.3 medium AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint…
- CVE-2026-92584 CVSS 5.3 medium AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter…
- CVE-2026-92583 CVSS 6.9 medium AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters…
- CVE-2026-92582 CVSS 7.1 high AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables…
- CVE-2026-92581 CVSS 5.3 medium In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed…
- CVE-2026-92580 CVSS 8.7 high In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line…
- CVE-2026-92579 CVSS 5.3 medium In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context…
- CVE-2026-92578 CVSS 9.2 critical WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login…
- CVE-2026-92577 CVSS 8.7 high In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that…
- CVE-2026-91967 CVSS 5.3 medium AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues…
- CVE-2026-91966 CVSS 6.9 medium AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that…
- CVE-2026-91965 CVSS 8.7 high WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php…
- CVE-2026-90552 CVSS 5.3 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the…
- CVE-2026-90551 CVSS 6.9 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API…
- CVE-2026-90550 CVSS 6.9 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins…
- CVE-2026-90549 CVSS 6.9 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php…
- CVE-2026-90548 CVSS 6.9 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php…
- CVE-2026-90547 CVSS 6.9 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin…
- CVE-2026-90546 CVSS 5.3 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php…
- CVE-2026-90545 CVSS 5.3 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the…
- CVE-2026-90544 CVSS 5.3 medium WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the…
- CVE-2026-90543 CVSS 6.9 medium WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing…