VendorsWWBNavideoall versions
Vulnerabilities

WWBN AVideo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

190CVEs
CVE-2026-33293
AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter
Published 2026-03-22 · Analyzed
8.1EPSS 0.006
CVE-2026-33038
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
Published 2026-03-20 · Analyzed
8.1EPSS 0.005
CVE-2026-41056
AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover
Published 2026-04-21 · Analyzed
8.1EPSS 0.005
CVE-2026-33493
AVideo has a Path Traversal in import.json.php that Allows Private Video Theft and Arbitrary File Read/Deletion via fileURI Parameter
Published 2026-03-23 · Analyzed
8.1EPSS 0.004
CVE-2026-33043
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
Published 2026-03-20 · Analyzed
8.1EPSS 0.004
CVE-2026-34394
AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
Published 2026-03-31 · Analyzed
8.1EPSS 0.003
CVE-2026-33488
AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin
Published 2026-03-23 · Analyzed
8.1EPSS 0.003
CVE-2025-34438
AVideo < 20.1 IDOR Arbitrary Video Rotation
Published 2025-12-17 · Modified
8.1EPSS 0.003
CVE-2023-30860
WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account
Published 2023-05-08 · Modified
8.0EPSS 0.007
CVE-2026-41060
AVideo's SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
Published 2026-04-21 · Analyzed
7.7EPSS 0.004
CVE-2026-39369
WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
Published 2026-04-07 · Analyzed
7.6EPSS 0.005
CVE-2026-33354
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
Published 2026-03-23 · Analyzed
7.6EPSS 0.003
CVE-2026-33650
AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
Published 2026-03-23 · Analyzed
7.6EPSS 0.003
CVE-2020-23490
There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
Published 2020-11-16 · Modified
7.5EPSS 0.026
CVE-2022-32777
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerabilty is for the session cookie which can be leaked via JavaScript.
Published 2022-08-22 · Modified
7.5EPSS 0.024
CVE-2022-32778
An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerability is for the pass cookie, which contains the hashed password and can be leaked via JavaScript.
Published 2022-08-22 · Modified
7.5EPSS 0.024
CVE-2023-49738
An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.
Published 2024-01-10 · Modified
7.5EPSS 0.013
CVE-2025-34441
AVideo < 20.1 User Information Disclosure via Public API
Published 2025-12-17 · Modified
7.5EPSS 0.009
CVE-2025-34442
AVideo < 20.1 System Path Disclosure via Public API
Published 2025-12-17 · Modified
7.5EPSS 0.009
CVE-2026-33483
AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php
Published 2026-03-23 · Analyzed
7.5EPSS 0.007
CVE-2026-34731
AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php
Published 2026-03-31 · Analyzed
7.5EPSS 0.006
CVE-2026-33292
AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Videos
Published 2026-03-22 · Analyzed
7.5EPSS 0.006
CVE-2026-33485
AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter
Published 2026-03-23 · Analyzed
7.5EPSS 0.005
CVE-2026-34732
AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints
Published 2026-03-31 · Analyzed
7.5EPSS 0.004
CVE-2026-33319
AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command
Published 2026-03-22 · Analyzed
7.5EPSS 0.004
CVE-2026-33512
AVideo has an unauthenticated decrypt oracle leaking any ciphertext
Published 2026-03-23 · Analyzed
7.5EPSS 0.003
CVE-2023-49810
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to brute force user credentials. An attacker can send a series of HTTP requests to trigger this vulnerability.
Published 2024-01-10 · Modified
7.3EPSS 0.007
CVE-2026-33492
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
Published 2026-03-23 · Analyzed
7.3EPSS 0.004
CVE-2026-34733
AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard
Published 2026-03-31 · Analyzed
7.3EPSS 0.004
CVE-2026-33681
AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name
Published 2026-03-23 · Analyzed
7.2EPSS 0.006
CVE-2026-39370
WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732)
Published 2026-04-07 · Analyzed
7.1EPSS 0.003
CVE-2026-33723
AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php
Published 2026-03-23 · Analyzed
7.1EPSS 0.002
CVE-2026-40926
WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
Published 2026-04-21 · Analyzed
7.1EPSS 0.002
CVE-2026-41057
AVideo has CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) that Exposes Authenticated API Responses
Published 2026-04-21 · Analyzed
7.1EPSS 0.002
CVE-2026-47696
WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint
Published 2026-05-29 · Analyzed
7.1EPSS 0.002
CVE-2026-45731
WWBN AVideo: Authenticated Arbitrary File Read in view/update.php
Published 2026-05-29 · Analyzed
6.9EPSS 0.006
CVE-2026-46337
WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Published 2026-05-29 · Analyzed
6.9EPSS 0.006
CVE-2022-32761
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
6.5EPSS 0.028
CVE-2022-28710
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.
Published 2022-08-22 · Modified
6.5EPSS 0.027
CVE-2023-49862
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_gifimage` parameter.
Published 2024-01-10 · Modified
6.5EPSS 0.011
← Prev3 / 5Next →