wwbn/avideo
Packagist142 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting wwbn/avideopage 1 of 3
- CVE-2020-23489HIGHCVSS 8.8EG 8.8✓ Fixed in 8.92020-11-16
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate pri…
- CVE-2022-27463MEDIUMCVSS 6.1EG 6.12022-04-05
vulnerable: 10.4 ... 11.6 (7 versions)
Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url to the login page.
- CVE-2023-25313CRITICALCVSS 9.8EG 9.8✓ Fixed in 12.42023-04-25
vulnerable: 10.4 ... 11.6 (7 versions)
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
- CVE-2023-30854HIGHCVSS 8.8EG 8.8✓ Fixed in 12.42023-04-28
vulnerable: 10.4 ... 11.6 (7 versions)
AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite/cloneClient.json.php` allows attackers to achieve Remote Code Execution. This issue is fi…
- CVE-2023-30860HIGHCVSS 8.0EG 8.0✓ Fixed in 12.42023-05-08
vulnerable: 10.4 ... 11.6 (7 versions)
WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite another user in that Meeting, but it does not properly sanitize the malicious characters whe…
- CVE-2023-32073HIGHCVSS 8.8EG 8.82023-05-12
vulnerable: 10.4 ... 12.4 (8 versions)
WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.json.php` which allows Remote Code Execution if you CloneSite Plugin. This is a bypass to t…
- CVE-2023-49599CRITICALCVSS 9.8EG 9.82024-01-10
vulnerable: 10.4 ... 12.4 (8 versions)
An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted series of HTTP requests can lead to privilege escalation. An attacker can gather system info…
- CVE-2023-49810HIGHCVSS 7.3EG 7.32024-01-10
vulnerable: 10.4 ... 12.4 (8 versions)
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to captcha bypass, which can be abused by an attacker to…
- CVE-2023-50172MEDIUMCVSS 5.3EG 5.32024-01-10
vulnerable: 10.4 ... 12.4 (8 versions)
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pas…
- CVE-2024-31819CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.32024-04-10
vulnerable: 12.4
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
- CVE-2024-34899MEDIUMCVSS 5.4EG 5.4✓ Fixed in 14.32024-05-14
vulnerable: 10.4 ... 12.4 (8 versions)
WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).
- CVE-2026-27568MEDIUMCVSS 6.1EG 6.1✓ Fixed in 21.02026-02-24
vulnerable: 10.4 ... 18.0 (12 versions)
WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Safe Mode enabled. Markdown links are not sufficiently sanitized, allowing `javascript:` URIs…
- CVE-2026-27732HIGHCVSS 8.1EG 8.12026-02-24
vulnerable: 10.4 ... 21.0 (13 versions)
WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and fetches the referenced resource server-side without proper validation or an allow-list. Th…
- CVE-2026-28501CRITICALCVSS 9.8EG 9.82026-03-06
vulnerable: 10.4 ... 21.0 (13 versions)
WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly san…
- CVE-2026-28502HIGHCVSS 8.8EG 8.82026-03-06
vulnerable: 10.4 ... 21.0 (13 versions)
WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVideo related to the plugin upload/import functionality. The issue allowed an authenticated …
- CVE-2026-29058CRITICALCVSS 9.8EG 9.8✓ Fixed in 7.0.02026-03-06
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full …
- CVE-2026-29093CRITICALCVSS 9.8EG 9.82026-03-06
vulnerable: 10.4 ... 21.0 (13 versions)
WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 11211 (0.0.0.0:11211) with no authentication, while the Dockerfile configures PHP to store al…
- CVE-2026-30885MEDIUMCVSS 5.3EG 5.3✓ Fixed in 25.02026-03-10
vulnerable: 10.4 ... 24.0 (15 versions)
WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user without requiring authentication or authorization. An unauthenticated attacker can enumerate u…
- CVE-2026-33035MEDIUMCVSS 6.1EG 6.12026-03-20
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser. User input from a URL parameter f…
- CVE-2026-33038HIGHCVSS 8.1EG 8.12026-03-20
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfiguration.php endpoint. install/checkConfiguration.php performs full application init…
- CVE-2026-33039HIGHCVSS 8.6EG 8.62026-03-20
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal/private networks using isSSRFSafeURL(), but only checks the initial URL. When t…
- CVE-2026-33041MEDIUMCVSS 5.3EG 5.32026-03-20
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing algorithm to any unauthenticated user. An attacker can submit arbitrary passwords and receiv…
- CVE-2026-33043HIGHCVSS 8.1EG 8.12026-03-20
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Acces…
- CVE-2026-33237MEDIUMCVSS 5.5EG 5.5✓ Fixed in 26.02026-03-21
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by …
- CVE-2026-33238MEDIUMCVSS 4.3EG 4.3✓ Fixed in 26.02026-03-21
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob()` without restricting the path to an allowed base directory. An authent…
- CVE-2026-33292HIGHCVSS 7.5EG 7.52026-03-22
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the pl…
- CVE-2026-33293HIGHCVSS 8.1EG 8.12026-03-22
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credent…
- CVE-2026-33294MEDIUMCVSS 4.3EG 5.02026-03-22
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all …
- CVE-2026-33295MEDIUMCVSS 5.4EG 5.42026-03-22
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated…
- CVE-2026-33296MEDIUMCVSS 6.1EG 6.12026-03-22
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.locati…
- CVE-2026-33297CRITICALCVSS 9.1EG 9.12026-03-23
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted pa…
- CVE-2026-33319HIGHCVSS 7.5EG 7.52026-03-22
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API re…
- CVE-2026-33351CRITICALCVSS 9.1EG 9.12026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (t…
- CVE-2026-33352CRITICALCVSS 9.8EG 9.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowCats` request parameter is sanitized onl…
- CVE-2026-33354HIGHCVSS 6.5EG 7.62026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that …
- CVE-2026-33478CRITICALCVSS 10.0EG 10.02026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `…
- CVE-2026-33479HIGHCVSS 8.8EG 8.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user input from `$_REQUEST['sections']` array values directly into PHP's `eval()` func…
- CVE-2026-33480HIGHCVSS 8.6EG 8.62026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`). The unauthenticated `plugin/LiveLinks/proxy.p…
- CVE-2026-33482HIGHCVSS 8.1EG 8.12026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping…
- CVE-2026-33483HIGHCVSS 7.5EG 7.52026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An …
- CVE-2026-33485HIGHCVSS 7.5EG 7.52026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpo…
- CVE-2026-33488HIGHCVSS 8.1EG 8.12026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An atta…
- CVE-2026-33492HIGHCVSS 7.3EG 7.32026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session reg…
- CVE-2026-33493HIGHCVSS 8.1EG 8.12026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `ob…
- CVE-2026-33499MEDIUMCVSS 6.1EG 6.12026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` parameter directly into an HTML `<input>` tag's…
- CVE-2026-33500MEDIUMCVSS 5.4EG 5.42026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `<a>` and `<img>` tags in comme…
- CVE-2026-33501MEDIUMCVSS 5.3EG 5.32026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated use…
- CVE-2026-33502CRITICALCVSS 8.2EG 9.32026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests …
- CVE-2026-33507HIGHCVSS 8.8EG 8.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF p…
- CVE-2026-33512HIGHCVSS 7.5EG 7.52026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued public…
Check whether wwbn/avideo is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for wwbn/avideo CVEs against the assets you own.
Start Free Scan →