VendorsWWBNavideoany version
Vulnerabilities

WWBN AVideo any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

146CVEs
CVE-2026-33478
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
Published 2026-03-23 · Analyzed
10.0EPSS 0.112
CVE-2026-40911
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
Published 2026-04-21 · Analyzed
10.0EPSS 0.009
CVE-2024-31819
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
Published 2024-04-10 · Analyzed
9.8EPSS 0.156
CVE-2026-41304
WWBN AVideo vulnerable to RCE caused by clonesite plugin
Published 2026-04-21 · Analyzed
9.8EPSS 0.027
CVE-2026-28501
WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
Published 2026-03-06 · Analyzed
9.8EPSS 0.014
CVE-2023-25313
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
Published 2023-04-25 · Modified
9.8EPSS 0.013
CVE-2026-29093
WWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached port
Published 2026-03-06 · Analyzed
9.8EPSS 0.006
CVE-2026-33770
AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables
Published 2026-03-27 · Analyzed
9.8EPSS 0.006
CVE-2026-33352
AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)
Published 2026-03-23 · Analyzed
9.8EPSS 0.005
CVE-2026-33716
AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
Published 2026-03-23 · Analyzed
9.4EPSS 0.006
CVE-2026-28502
WWBN AVideo: Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction
Published 2026-03-06 · Analyzed
9.3EPSS 0.010
CVE-2026-41064
AVideo has an incomplete fix for CVE-2026-33502 (Command Injection)
Published 2026-04-21 · Analyzed
9.3EPSS 0.005
CVE-2025-34434
AVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and Deletion
Published 2025-12-17 · Modified
9.3EPSS 0.005
CVE-2026-33502
AVideo has Unauthenticated SSRF via plugin/Live/test.php
Published 2026-03-23 · Analyzed
9.3EPSS 0.004
CVE-2026-33351
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
Published 2026-03-23 · Analyzed
9.1EPSS 0.005
CVE-2026-34374
AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key
Published 2026-03-27 · Analyzed
9.1EPSS 0.005
CVE-2026-33297
AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.php
Published 2026-03-23 · Analyzed
9.1EPSS 0.005
CVE-2026-33867
AVideo has Plaintext Video Password Storage
Published 2026-03-27 · Analyzed
9.1EPSS 0.002
CVE-2023-32073
AVideo command injection vulnerability
Published 2023-05-12 · Modified
8.8EPSS 0.065
CVE-2023-30854
WWBN AVideo vulnerable to OS Command Injection
Published 2023-04-28 · Modified
8.8EPSS 0.052
CVE-2020-23489
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
Published 2020-11-16 · Modified
8.8EPSS 0.023
CVE-2026-33648
AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path
Published 2026-03-23 · Analyzed
8.8EPSS 0.009
CVE-2026-33647
AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload
Published 2026-03-23 · Analyzed
8.8EPSS 0.008
CVE-2021-21286
Authorization Bypass in AVideo Platform
Published 2021-02-01 · Modified
8.8EPSS 0.008
CVE-2026-33479
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
Published 2026-03-23 · Analyzed
8.8EPSS 0.007
CVE-2026-33767
AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query
Published 2026-03-27 · Analyzed
8.8EPSS 0.006
CVE-2026-33717
AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort
Published 2026-03-23 · Analyzed
8.8EPSS 0.005
CVE-2026-45578
WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
Published 2026-05-29 · Analyzed
8.8EPSS 0.005
CVE-2026-33651
AVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_id in Scheduler_commands::getAllActiveOrToRepeat()
Published 2026-03-23 · Analyzed
8.8EPSS 0.005
CVE-2025-34436
AVideo < 20.1 IDOR Arbitrary File Upload
Published 2025-12-17 · Modified
8.8EPSS 0.004
CVE-2025-34437
AVideo < 20.1 IDOR Arbitrary Comment Image Upload
Published 2025-12-17 · Modified
8.8EPSS 0.004
CVE-2026-33507
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
Published 2026-03-23 · Analyzed
8.8EPSS 0.003
CVE-2026-33649
AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification
Published 2026-03-23 · Analyzed
8.8EPSS 0.002
CVE-2026-40909
WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)
Published 2026-04-21 · Analyzed
8.7EPSS 0.008
CVE-2025-34435
AVideo < 20.1 IDOR Arbitrary File Deletion
Published 2025-12-17 · Modified
8.7EPSS 0.003
CVE-2026-33513
AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)
Published 2026-03-23 · Analyzed
8.6EPSS 0.007
CVE-2026-33719
AVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment in status.json.php
Published 2026-03-23 · Analyzed
8.6EPSS 0.005
CVE-2026-33039
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
Published 2026-03-20 · Analyzed
8.6EPSS 0.005
CVE-2026-41055
AVideo has an incomplete fix for CVE-2026-33039 (SSRF)
Published 2026-04-21 · Analyzed
8.6EPSS 0.004
CVE-2026-27732
AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php
Published 2026-02-24 · Analyzed
8.6EPSS 0.004
1 / 4Next →