VendorsWWBNavideoany version
Vulnerabilities

WWBN AVideo any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

146CVEs
CVE-2023-49862
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_gifimage` parameter.
Published 2024-01-10 · Modified
6.5EPSS 0.011
CVE-2023-49863
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary file read.This vulnerability is triggered by the `downloadURL_webpimage` parameter.
Published 2024-01-10 · Modified
6.5EPSS 0.011
CVE-2026-41062
WWBN/AVideo has an incomplete fix for a directory traversal bypass via query string in ReceiveImage downloadURL parameters
Published 2026-04-21 · Analyzed
6.5EPSS 0.009
CVE-2026-40907
WWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens
Published 2026-04-21 · Analyzed
6.5EPSS 0.004
CVE-2026-34395
AVideo: Mass User PII Disclosure via Missing Authorization in YPTWallet users.json.php
Published 2026-03-31 · Analyzed
6.5EPSS 0.004
CVE-2026-34740
AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation
Published 2026-03-31 · Analyzed
6.5EPSS 0.004
CVE-2026-39368
WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services
Published 2026-04-07 · Analyzed
6.5EPSS 0.003
CVE-2026-34737
AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug
Published 2026-03-31 · Analyzed
6.5EPSS 0.003
CVE-2026-33766
AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints
Published 2026-03-27 · Analyzed
6.5EPSS 0.003
CVE-2026-34613
AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins
Published 2026-03-31 · Analyzed
6.5EPSS 0.003
CVE-2026-45619
AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post
Published 2026-05-29 · Analyzed
6.5EPSS 0.002
CVE-2026-39366
WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php
Published 2026-04-07 · Analyzed
6.5EPSS 0.002
CVE-2026-34611
AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users
Published 2026-03-31 · Analyzed
6.5EPSS 0.002
CVE-2026-45610
WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
Published 2026-05-29 · Analyzed
6.5EPSS 0.002
CVE-2026-34716
AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification
Published 2026-03-31 · Analyzed
6.4EPSS 0.003
CVE-2026-34245
AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking
Published 2026-03-27 · Analyzed
6.3EPSS 0.003
CVE-2022-27463
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
Published 2022-04-05 · Modified
6.1EPSS 0.006
CVE-2022-27462
Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to view/include/head.php.
Published 2022-04-05 · Modified
6.1EPSS 0.006
CVE-2023-25314
Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the success parameter to /user.
Published 2023-04-25 · Modified
6.1EPSS 0.004
CVE-2026-33035
Unauthenticated Reflected XSS via innerHTML in AVideo
Published 2026-03-20 · Analyzed
6.1EPSS 0.004
CVE-2026-27568
AVideo has Stored Cross-Site Scripting via Markdown Comment Injection
Published 2026-02-24 · Analyzed
6.1EPSS 0.003
CVE-2026-33499
AVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPage.php
Published 2026-03-23 · Analyzed
6.1EPSS 0.003
CVE-2026-34396
AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel
Published 2026-03-31 · Analyzed
6.1EPSS 0.003
CVE-2026-34739
AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php
Published 2026-03-31 · Analyzed
6.1EPSS 0.003
CVE-2026-33296
AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php
Published 2026-03-22 · Analyzed
6.1EPSS 0.003
CVE-2025-34439
AVideo < 20.1 Open Redirect via cancelUri Parameter
Published 2025-12-17 · Modified
6.1EPSS 0.002
CVE-2025-34440
AVideo < 20.1 Open Redirect via siteRedirectUri Parameter
Published 2025-12-17 · Modified
6.1EPSS 0.002
CVE-2026-30885
WWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure
Published 2026-03-09 · Analyzed
5.5EPSS 0.004
CVE-2026-33237
AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation
Published 2026-03-20 · Modified
5.5EPSS 0.004
CVE-2024-34899
WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
Published 2024-05-13 · Analyzed
5.4EPSS 0.005
CVE-2026-41063
WWBN AVideo has incomplete fix for CVE-2026-33500 (XSS)
Published 2026-04-21 · Analyzed
5.4EPSS 0.003
CVE-2026-34247
AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream Posters and Trigger False Socket Notifications
Published 2026-03-27 · Analyzed
5.4EPSS 0.003
CVE-2026-34362
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()
Published 2026-03-27 · Analyzed
5.4EPSS 0.003
CVE-2026-33500
AVideo Vulnerable to Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWithLinks Sanitization
Published 2026-03-23 · Analyzed
5.4EPSS 0.003
CVE-2026-33683
AVideo vulnerable to Stored XSS via html_entity_decode() Reversing xss_esc() Sanitization in Channel About Field
Published 2026-03-23 · Analyzed
5.4EPSS 0.002
CVE-2026-41061
WWBN AVideo Vulnerable to stored XSS via Unanchored Duration Regex in Video Encoder Receiver
Published 2026-04-21 · Analyzed
5.4EPSS 0.002
CVE-2026-47694
WWBN AVideo: Stored XSS via unescaped Gallery category description
Published 2026-05-29 · Analyzed
5.4EPSS 0.002
CVE-2026-39367
WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page
Published 2026-04-07 · Analyzed
5.4EPSS 0.002
CVE-2026-45580
WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute
Published 2026-05-29 · Analyzed
5.4EPSS 0.002
CVE-2026-40929
WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators
Published 2026-04-21 · Analyzed
5.4EPSS 0.001
← Prev3 / 4Next →