VYPR
Vendor

WWBN

WWBN is a radio station broadcasting mainstream rock to Flint and The Thumb areas of Michigan. Syndicated shows on Banana include the morning comedy program The Free Beer and Hot Wings Show and the nightly music program Loudwire. It is owned by Townsquare Media and is a member of the Michigan Association of Broadcasters

Founded 1994
Products
5
CVEs
344
Across products
346
Status
Private

Products

5

Recent CVEs

344
View all 344 CVEs →
  • CVE-2022-30547CriAug 22, 2022
    risk 0.69cvss 9.9epss 0.64

    A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2026-86189CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.01

    WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext…

  • CVE-2026-85154CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it…

  • CVE-2026-84480CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's…

  • CVE-2023-47862CriJan 10, 2024
    risk 0.64cvss 9.8epss 0.01

    A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send a series of HTTP requests to trigger this…

  • CVE-2023-48728CriJan 10, 2024
    risk 0.63cvss 9.6epss 0.02

    A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to…

  • CVE-2022-30534HigAug 22, 2022
    risk 0.63cvss 8.8epss 0.75

    An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this…

  • CVE-2022-26842CriAug 22, 2022
    risk 0.63cvss 9.6epss 0.04

    A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to…

  • CVE-2025-50128CriJul 24, 2025
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a…

  • CVE-2025-46410CriJul 24, 2025
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to…

  • CVE-2025-41420CriJul 24, 2025
    risk 0.62cvss 9.6epss 0.01

    A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to…

  • CVE-2024-31819CriApr 10, 2024
    risk 0.61cvss 9.8epss 0.16

    An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.

  • CVE-2026-29058CriMar 6, 2026
    risk 0.60cvss 9.8epss 0.02

    AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration…

  • CVE-2026-28501CriMar 6, 2026
    risk 0.60cvss 9.8epss 0.01

    WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the catName parameter when it is…

  • CVE-2026-86190CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.00

    WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the…

  • CVE-2026-84479CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.01

    WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp")…

  • CVE-2026-34374CriMar 27, 2026
    risk 0.59cvss 9.1epss 0.01

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is called as a fallback from…

  • CVE-2026-33478CriMar 23, 2026
    risk 0.59cvss 10.0epss 0.11

    WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone…

  • CVE-2025-53084CriJul 24, 2025
    risk 0.59cvss 9.0epss 0.01

    A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to…

  • CVE-2023-47861CriJan 10, 2024
    risk 0.59cvss 9.0epss 0.01

    A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb. A specially crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get a user to visit a webpage to…