VendorsWWBNavideoall versions
Vulnerabilities

WWBN AVideo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

190CVEs
CVE-2026-33478
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
Published 2026-03-23 · Analyzed
10.0EPSS 0.112
CVE-2026-40911
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
Published 2026-04-21 · Analyzed
10.0EPSS 0.009
CVE-2022-30534
An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
9.9EPSS 0.750
CVE-2022-30547
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
9.9EPSS 0.637
CVE-2022-32572
An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
9.9EPSS 0.244
CVE-2024-31819
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
Published 2024-04-10 · Analyzed
9.8EPSS 0.156
CVE-2026-41304
WWBN AVideo vulnerable to RCE caused by clonesite plugin
Published 2026-04-21 · Analyzed
9.8EPSS 0.027
CVE-2026-28501
WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
Published 2026-03-06 · Analyzed
9.8EPSS 0.014
CVE-2023-25313
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
Published 2023-04-25 · Modified
9.8EPSS 0.013
CVE-2025-48732
An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can request a .phar file to trigger this vulnerability.
Published 2025-07-24 · Modified
9.8EPSS 0.011
CVE-2023-47862
A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests to trigger this vulnerability.
Published 2024-01-10 · Modified
9.8EPSS 0.011
CVE-2023-49599
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system information via HTTP requests and brute force the salt offline, leading to forging a legitimate password recovery code for the admin user.
Published 2024-01-10 · Modified
9.8EPSS 0.010
CVE-2020-37172
AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
Published 2026-02-11 · Analyzed
9.8EPSS 0.007
CVE-2026-29093
WWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
Published 2026-03-06 · Analyzed
9.8EPSS 0.006
CVE-2026-33770
AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables
Published 2026-03-27 · Analyzed
9.8EPSS 0.006
CVE-2026-33352
AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)
Published 2026-03-23 · Analyzed
9.8EPSS 0.005
CVE-2022-30690
A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
9.6EPSS 0.839
CVE-2022-32770
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "toast" parameter which is inserted into the document with insufficient sanitization.
Published 2022-08-22 · Modified
9.6EPSS 0.044
CVE-2022-32771
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.
Published 2022-08-22 · Modified
9.6EPSS 0.042
CVE-2022-32772
A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "msg" parameter which is inserted into the document with insufficient sanitization.
Published 2022-08-22 · Modified
9.6EPSS 0.040
CVE-2022-26842
A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
9.6EPSS 0.039
CVE-2023-48728
A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2024-01-10 · Modified
9.6EPSS 0.023
CVE-2025-41420
A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2025-07-24 · Modified
9.6EPSS 0.012
CVE-2025-36548
A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2025-07-24 · Modified
9.6EPSS 0.010
CVE-2025-46410
A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2025-07-24 · Modified
9.6EPSS 0.008
CVE-2025-50128
A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2025-07-24 · Modified
9.6EPSS 0.008
CVE-2026-33716
AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
Published 2026-03-23 · Analyzed
9.4EPSS 0.006
CVE-2026-28502
WWBN AVideo: Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction
Published 2026-03-06 · Analyzed
9.3EPSS 0.010
CVE-2026-41064
AVideo has an incomplete fix for CVE-2026-33502 (Command Injection)
Published 2026-04-21 · Analyzed
9.3EPSS 0.005
CVE-2025-34434
AVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and Deletion
Published 2025-12-17 · Modified
9.3EPSS 0.005
CVE-2026-33502
AVideo has Unauthenticated SSRF via plugin/Live/test.php
Published 2026-03-23 · Analyzed
9.3EPSS 0.004
CVE-2026-33351
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
Published 2026-03-23 · Analyzed
9.1EPSS 0.005
CVE-2026-34374
AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key
Published 2026-03-27 · Analyzed
9.1EPSS 0.005
CVE-2026-33297
AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php
Published 2026-03-23 · Analyzed
9.1EPSS 0.005
CVE-2026-33867
AVideo has Plaintext Video Password Storage
Published 2026-03-27 · Analyzed
9.1EPSS 0.002
CVE-2022-28712
A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
9.0EPSS 0.031
CVE-2023-47861
A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2024-01-10 · Modified
9.0EPSS 0.008
CVE-2025-53084
A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2025-07-24 · Modified
9.0EPSS 0.007
CVE-2023-32073
AVideo command injection vulnerability
Published 2023-05-12 · Modified
8.8EPSS 0.065
CVE-2023-30854
WWBN AVideo vulnerable to OS Command Injection
Published 2023-04-28 · Modified
8.8EPSS 0.052
1 / 5Next →