VendorsWWBNavideoall versions
Vulnerabilities

WWBN AVideo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

190CVEs
CVE-2022-30605
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
8.8EPSS 0.049
CVE-2020-23489
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
Published 2020-11-16 · Modified
8.8EPSS 0.023
CVE-2022-33149
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the CloneSite plugin, allowing an attacker to inject SQL by manipulating the url parameter.
Published 2022-08-22 · Modified
8.8EPSS 0.019
CVE-2022-33147
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the aVideoEncoder functionality which can be used to add new videos, allowing an attacker to inject SQL by manipulating the videoDownloadedLink or duration parameter.
Published 2022-08-22 · Modified
8.8EPSS 0.019
CVE-2022-32282
An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' password hash will be able to use it to directly login into the account, leading to increased privileges.
Published 2022-08-22 · Modified
8.8EPSS 0.018
CVE-2022-29468
A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
8.8EPSS 0.017
CVE-2023-49715
A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution when chained with an LFI vulnerability. An attacker can send a series of HTTP requests to trigger this vulnerability.
Published 2024-01-10 · Modified
8.8EPSS 0.014
CVE-2022-33148
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the title parameter.
Published 2022-08-22 · Modified
8.8EPSS 0.012
CVE-2022-34652
A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the description parameter.
Published 2022-08-22 · Modified
8.8EPSS 0.011
CVE-2025-25214
A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series of specially crafted HTTP request can lead to arbitrary code execution.
Published 2025-07-24 · Modified
8.8EPSS 0.010
CVE-2023-49589
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
Published 2024-01-10 · Modified
8.8EPSS 0.009
CVE-2026-33648
AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path
Published 2026-03-23 · Analyzed
8.8EPSS 0.009
CVE-2026-33647
AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload
Published 2026-03-23 · Analyzed
8.8EPSS 0.008
CVE-2021-21286
Authorization Bypass in AVideo Platform
Published 2021-02-01 · Modified
8.8EPSS 0.008
CVE-2026-33479
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
Published 2026-03-23 · Analyzed
8.8EPSS 0.007
CVE-2026-33767
AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query
Published 2026-03-27 · Analyzed
8.8EPSS 0.006
CVE-2026-33717
AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort
Published 2026-03-23 · Analyzed
8.8EPSS 0.005
CVE-2026-45578
WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
Published 2026-05-29 · Analyzed
8.8EPSS 0.005
CVE-2026-33651
AVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_id in Scheduler_commands::getAllActiveOrToRepeat()
Published 2026-03-23 · Analyzed
8.8EPSS 0.005
CVE-2025-34436
AVideo < 20.1 IDOR Arbitrary File Upload
Published 2025-12-17 · Modified
8.8EPSS 0.004
CVE-2025-34437
AVideo < 20.1 IDOR Arbitrary Comment Image Upload
Published 2025-12-17 · Modified
8.8EPSS 0.004
CVE-2026-33507
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
Published 2026-03-23 · Analyzed
8.8EPSS 0.003
CVE-2020-37158
AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
Published 2026-02-11 · Modified
8.8EPSS 0.002
CVE-2026-33649
AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification
Published 2026-03-23 · Analyzed
8.8EPSS 0.002
CVE-2026-40909
WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)
Published 2026-04-21 · Analyzed
8.7EPSS 0.008
CVE-2020-37173
AVideo Platform 8.1 - Information Disclosure (User Enumeration)
Published 2026-02-11 · Analyzed
8.7EPSS 0.006
CVE-2025-34435
AVideo < 20.1 IDOR Arbitrary File Deletion
Published 2025-12-17 · Modified
8.7EPSS 0.003
CVE-2026-33513
AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)
Published 2026-03-23 · Analyzed
8.6EPSS 0.007
CVE-2026-33719
AVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment in status.json.php
Published 2026-03-23 · Analyzed
8.6EPSS 0.005
CVE-2026-33039
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
Published 2026-03-20 · Analyzed
8.6EPSS 0.005
CVE-2026-41055
AVideo has an incomplete fix for CVE-2026-33039 (SSRF)
Published 2026-04-21 · Analyzed
8.6EPSS 0.004
CVE-2026-27732
AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php
Published 2026-02-24 · Analyzed
8.6EPSS 0.004
CVE-2026-33480
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
Published 2026-03-23 · Analyzed
8.6EPSS 0.004
CVE-2023-48730
A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to trigger this vulnerability.
Published 2024-01-10 · Modified
8.5EPSS 0.006
CVE-2026-40925
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
Published 2026-04-21 · Analyzed
8.3EPSS 0.002
CVE-2026-34375
AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page
Published 2026-03-27 · Analyzed
8.2EPSS 0.003
CVE-2026-33295
AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php
Published 2026-03-22 · Analyzed
8.2EPSS 0.002
CVE-2026-33482
AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()
Published 2026-03-23 · Analyzed
8.1EPSS 0.047
CVE-2026-33037
WWBN AVideo has predictable default admin credentials in official Docker deployment path
Published 2026-03-20 · Analyzed
8.1EPSS 0.007
CVE-2026-41058
AVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideo
Published 2026-04-21 · Analyzed
8.1EPSS 0.007
← Prev2 / 5Next →