VendorsWWBNavideoall versions
Vulnerabilities

WWBN AVideo

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

190CVEs
CVE-2026-40928
AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion
Published 2026-04-21 · Analyzed
5.4EPSS 0.001
CVE-2026-40929
WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators
Published 2026-04-21 · Analyzed
5.4EPSS 0.001
CVE-2023-50172
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.
Published 2024-01-10 · Modified
5.3EPSS 0.008
CVE-2026-33501
AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions Plugin
Published 2026-03-23 · Analyzed
5.3EPSS 0.005
CVE-2026-33761
AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings
Published 2026-03-27 · Analyzed
5.3EPSS 0.004
CVE-2026-33685
AVideo Allows Unauthenticated Access to AD_Server reports.json.php that Exposes Ad Campaign Analytics and User Data
Published 2026-03-23 · Analyzed
5.3EPSS 0.004
CVE-2026-33763
AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean Oracle
Published 2026-03-27 · Analyzed
5.3EPSS 0.004
CVE-2026-33759
AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents
Published 2026-03-27 · Analyzed
5.3EPSS 0.004
CVE-2026-35450
WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php
Published 2026-04-06 · Analyzed
5.3EPSS 0.004
CVE-2026-35452
WWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php
Published 2026-04-06 · Analyzed
5.3EPSS 0.004
CVE-2026-34369
AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sources Without Password Verification
Published 2026-03-27 · Analyzed
5.3EPSS 0.004
CVE-2026-33688
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
Published 2026-03-23 · Analyzed
5.3EPSS 0.004
CVE-2026-33041
AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php
Published 2026-03-20 · Analyzed
5.3EPSS 0.004
CVE-2026-40908
WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php that Exposes Developer Emails and Deployed Version
Published 2026-04-21 · Analyzed
5.3EPSS 0.004
CVE-2026-35449
WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php
Published 2026-04-06 · Analyzed
5.3EPSS 0.003
CVE-2026-34364
AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.php
Published 2026-03-27 · Analyzed
5.3EPSS 0.003
CVE-2026-45620
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration
Published 2026-05-29 · Analyzed
5.3EPSS 0.003
CVE-2026-40935
WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
Published 2026-04-21 · Analyzed
5.3EPSS 0.003
CVE-2026-35179
WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php
Published 2026-04-06 · Analyzed
5.3EPSS 0.003
CVE-2026-33690
AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()
Published 2026-03-23 · Analyzed
5.3EPSS 0.003
CVE-2026-34368
AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance
Published 2026-03-27 · Analyzed
5.3EPSS 0.002
CVE-2022-32769
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Playlists plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's playlists.
Published 2022-08-22 · Modified
5.0EPSS 0.008
CVE-2026-33294
AVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resources
Published 2026-03-22 · Analyzed
5.0EPSS 0.003
CVE-2022-32768
Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request by an authenticated user can lead to unauthorized access and takeover of resources. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to bypass authentication by guessing a sequential ID, allowing them to take over the another user's streams.
Published 2022-08-22 · Modified
4.8EPSS 0.009
CVE-2026-33238
AVideo has a Path Traversal in listFiles.json.php that Enables Server Filesystem Enumeration
Published 2026-03-20 · Modified
4.3EPSS 0.004
CVE-2026-33764
AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcriptions
Published 2026-03-27 · Analyzed
4.3EPSS 0.003
CVE-2026-34738
AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter
Published 2026-03-31 · Analyzed
4.3EPSS 0.003
CVE-2026-35181
WWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php
Published 2026-04-06 · Analyzed
4.3EPSS 0.001
CVE-2026-35180
WWBN AVideo affected by CSRF on Site Customization Endpoint Enables Logo Overwrite via Base64 File Write
Published 2026-04-06 · Analyzed
4.3EPSS 0.001
CVE-2026-35448
WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php
Published 2026-04-06 · Analyzed
3.7EPSS 0.003
← Prev5 / 5