VYPR
Vendor

AVideo

Products
5
CVEs
25
Across products
27
Status
Private

Products

5

Recent CVEs

25
View all 25 CVEs →
  • CVE-2025-34433CriDec 19, 2025
    risk 0.57cvss epss 0.01

    AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installation salt using PHP uniqid(). The installation timestamp is exposed via a public endpoint, and a derived hash identifier is…

  • CVE-2023-25313CriApr 25, 2023
    risk 0.57cvss 9.8epss 0.01

    OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.

  • CVE-2026-33024CriMar 20, 2026
    risk 0.52cvss 9.1epss 0.00

    AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpoints getImage.php and getImageMP4.php. Both endpoints accept a base64Url GET parameter, base64-decode it, and pass the resulting…

  • CVE-2026-33025HigMar 20, 2026
    risk 0.50cvss 8.8epss 0.00

    AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_POST['sort'] array keys are used directly as SQL column identifiers inside an ORDER BY clause. Although real_escape_string() was…

  • CVE-2026-56341HigJun 20, 2026
    risk 0.49cvss 7.5epss 0.00

    AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction…

  • CVE-2020-37173HigFeb 11, 2026
    risk 0.49cvss 7.5epss 0.01

    AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. Attackers can retrieve sensitive user information including email, password hash, and administrative status by…

  • CVE-2021-25877HigNov 1, 2021
    risk 0.47cvss 7.2epss 0.02

    AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.

  • CVE-2026-81678HigAug 27, 2026
    risk 0.42cvss 7.5epss 0.00

    AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the…

  • CVE-2026-56347MedJun 20, 2026
    risk 0.40cvss 6.1epss 0.00

    AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers can inject malicious JavaScript through unescaped menu item fields that execute…

  • CVE-2021-25878MedNov 1, 2021
    risk 0.40cvss 6.1epss 0.01

    AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

  • CVE-2021-25876MedNov 1, 2021
    risk 0.40cvss 6.1epss 0.01

    AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

  • CVE-2026-57944MedAug 22, 2026
    risk 0.35cvss 5.4epss 0.00

    AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying…

  • CVE-2020-37172MedFeb 11, 2026
    risk 0.35cvss 5.3epss 0.01

    AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change…

  • CVE-2020-37158MedFeb 11, 2026
    risk 0.34cvss 5.3epss 0.00

    AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change…

  • CVE-2025-34442HigDec 17, 2025
    risk 0.03cvss 7.5epss 0.01

    AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to media files, revealing underlying filesystem structure and facilitating more effective attack chains.

  • CVE-2025-34441HigDec 17, 2025
    risk 0.03cvss 7.5epss 0.01

    AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, administrative status, and last login times, enabling user enumeration and privacy violations.

  • CVE-2026-60092MedJul 8, 2026
    risk 0.00cvss 6.1epss 0.00

    AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vulnerability in the Meet plugin's getMeetInfo.json.php endpoint. When a participant joins a public meeting, the raw HTTP User-Agent header is stored…

  • CVE-2025-34440MedDec 17, 2025
    risk 0.00cvss 6.1epss 0.00

    AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user registration. Attackers can redirect users to external sites, facilitating phishing attacks.

  • CVE-2025-34439MedDec 17, 2025
    risk 0.00cvss 6.1epss 0.00

    AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An attacker can craft a link to redirect users to arbitrary external sites, enabling phishing attacks.

  • CVE-2025-34438HigDec 17, 2025
    risk 0.00cvss 8.1epss 0.00

    AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce ownership or management rights for the…