VendorsWWBNavideoany version
Vulnerabilities

WWBN AVideo any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

146CVEs
CVE-2026-33480
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
Published 2026-03-23 · Analyzed
8.6EPSS 0.004
CVE-2026-40925
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
Published 2026-04-21 · Analyzed
8.3EPSS 0.002
CVE-2026-34375
AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page
Published 2026-03-27 · Analyzed
8.2EPSS 0.003
CVE-2026-33295
AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php
Published 2026-03-22 · Analyzed
8.2EPSS 0.002
CVE-2026-33482
AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()
Published 2026-03-23 · Analyzed
8.1EPSS 0.047
CVE-2026-33037
WWBN AVideo has predictable default admin credentials in official Docker deployment path
Published 2026-03-20 · Analyzed
8.1EPSS 0.007
CVE-2026-41058
AVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideo
Published 2026-04-21 · Analyzed
8.1EPSS 0.007
CVE-2026-33293
AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter
Published 2026-03-22 · Analyzed
8.1EPSS 0.006
CVE-2026-33038
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
Published 2026-03-20 · Analyzed
8.1EPSS 0.005
CVE-2026-41056
AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover
Published 2026-04-21 · Analyzed
8.1EPSS 0.005
CVE-2026-33493
AVideo has a Path Traversal in import.json.php that Allows Private Video Theft and Arbitrary File Read/Deletion via fileURI Parameter
Published 2026-03-23 · Analyzed
8.1EPSS 0.004
CVE-2026-33043
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
Published 2026-03-20 · Analyzed
8.1EPSS 0.004
CVE-2026-34394
AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
Published 2026-03-31 · Analyzed
8.1EPSS 0.003
CVE-2026-33488
AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin
Published 2026-03-23 · Analyzed
8.1EPSS 0.003
CVE-2025-34438
AVideo < 20.1 IDOR Arbitrary Video Rotation
Published 2025-12-17 · Modified
8.1EPSS 0.003
CVE-2023-30860
WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account
Published 2023-05-08 · Modified
8.0EPSS 0.007
CVE-2026-41060
AVideo's SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
Published 2026-04-21 · Analyzed
7.7EPSS 0.004
CVE-2026-39369
WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
Published 2026-04-07 · Analyzed
7.6EPSS 0.005
CVE-2026-33354
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
Published 2026-03-23 · Analyzed
7.6EPSS 0.003
CVE-2026-33650
AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
Published 2026-03-23 · Analyzed
7.6EPSS 0.003
CVE-2020-23490
There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
Published 2020-11-16 · Modified
7.5EPSS 0.026
CVE-2025-34441
AVideo < 20.1 User Information Disclosure via Public API
Published 2025-12-17 · Modified
7.5EPSS 0.009
CVE-2025-34442
AVideo < 20.1 System Path Disclosure via Public API
Published 2025-12-17 · Modified
7.5EPSS 0.009
CVE-2026-33483
AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php
Published 2026-03-23 · Analyzed
7.5EPSS 0.007
CVE-2026-34731
AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php
Published 2026-03-31 · Analyzed
7.5EPSS 0.006
CVE-2026-33292
AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos
Published 2026-03-22 · Analyzed
7.5EPSS 0.006
CVE-2026-33485
AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter
Published 2026-03-23 · Analyzed
7.5EPSS 0.005
CVE-2026-34732
AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints
Published 2026-03-31 · Analyzed
7.5EPSS 0.004
CVE-2026-33319
AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command
Published 2026-03-22 · Analyzed
7.5EPSS 0.004
CVE-2026-33512
AVideo has an unauthenticated decrypt oracle leaking any ciphertext
Published 2026-03-23 · Analyzed
7.5EPSS 0.003
CVE-2026-33492
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
Published 2026-03-23 · Analyzed
7.3EPSS 0.004
CVE-2026-34733
AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard
Published 2026-03-31 · Analyzed
7.3EPSS 0.004
CVE-2026-33681
AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name
Published 2026-03-23 · Analyzed
7.2EPSS 0.006
CVE-2026-39370
WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732)
Published 2026-04-07 · Analyzed
7.1EPSS 0.003
CVE-2026-33723
AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php
Published 2026-03-23 · Analyzed
7.1EPSS 0.002
CVE-2026-40926
WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
Published 2026-04-21 · Analyzed
7.1EPSS 0.002
CVE-2026-41057
AVideo has CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) that Exposes Authenticated API Responses
Published 2026-04-21 · Analyzed
7.1EPSS 0.002
CVE-2026-47696
WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint
Published 2026-05-29 · Analyzed
7.1EPSS 0.002
CVE-2026-45731
WWBN AVideo: Authenticated Arbitrary File Read in view/update.php
Published 2026-05-29 · Analyzed
6.9EPSS 0.006
CVE-2026-46337
WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Published 2026-05-29 · Analyzed
6.9EPSS 0.006
← Prev2 / 4Next →