VYPR

Avideo

by WWBN

Source repositories

CVEs (340)

  • CVE-2026-82645HigAug 30, 2026
    risk 0.56cvss 8.6epss 0.00

    AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the…

  • CVE-2026-33513HigMar 23, 2026
    risk 0.56cvss 8.6epss 0.01

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under…

  • CVE-2026-54458CriJul 15, 2026
    risk 0.55cvss 9.6epss 0.01

    WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin of every administrator currently…

  • CVE-2023-48730HigJan 10, 2024
    risk 0.55cvss 8.5epss 0.01

    A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to…

  • CVE-2026-33716CriMar 23, 2026
    risk 0.54cvss 9.4epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token…

  • CVE-2025-36548HigJul 24, 2025
    risk 0.54cvss 8.3epss 0.01

    A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to…

  • CVE-2026-92914HigSep 17, 2026
    risk 0.53cvss 8.1epss 0.00

    AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's password can bypass the second factor by sending…

  • CVE-2026-88869CriSep 10, 2026
    risk 0.53cvss 9.3epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through…

  • CVE-2026-86723HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.00

    AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit…

  • CVE-2026-85160HigSep 3, 2026
    risk 0.53cvss 8.1epss 0.00

    AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag…

  • CVE-2026-84187HigSep 1, 2026
    risk 0.53cvss 8.2epss 0.00

    AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP…

  • CVE-2026-83595HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.00

    AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to…

  • CVE-2026-56345HigJun 20, 2026
    risk 0.53cvss 8.1epss 0.00

    AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a…

  • CVE-2026-41064CriApr 22, 2026
    risk 0.53cvss 9.3epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation regex `/^http/` accepts…

  • CVE-2026-34394HigMar 31, 2026
    risk 0.53cvss 8.1epss 0.00

    WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before processing the request. Combined with…

  • CVE-2026-33649HigMar 23, 2026
    risk 0.53cvss 8.1epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and…

  • CVE-2026-33502CriMar 23, 2026
    risk 0.53cvss 9.3epss 0.00

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to…

  • CVE-2026-72748CriAug 11, 2026
    risk 0.52cvss 9.1epss 0.01

    AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust…

  • CVE-2026-33351CriMar 23, 2026
    risk 0.52cvss 9.1epss 0.00

    WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended configuration for this…

  • CVE-2026-33297CriMar 23, 2026
    risk 0.52cvss 9.1epss 0.00

    WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password…

Page 3 of 17