wwbn/avideo
Packagist142 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting wwbn/avideopage 2 of 3
- CVE-2026-33513HIGHCVSS 7.5EG 8.62026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is …
- CVE-2026-33647HIGHCVSS 8.8EG 8.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using `finfo` MIME type detection but derives the saved filename extension from the u…
- CVE-2026-33648HIGHCVSS 8.8EG 8.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-controlled `users_id` and `liveTransmitionHistory_id` values from the JSON request bod…
- CVE-2026-33649HIGHCVSS 8.8EG 8.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The en…
- CVE-2026-33650HIGHCVSS 7.6EG 7.62026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privileges to perform full video management operations — including ownership transfer and dele…
- CVE-2026-33651HIGHCVSS 8.8EG 8.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint passes `$_REQUEST['live_schedule_id']` through multiple functions without sanitization until it reaches `Scheduler_command…
- CVE-2026-33681HIGHCVSS 7.2EG 7.22026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a `name` parameter via POST and passes it to `Plugin::getDatabaseFileName()` without any pa…
- CVE-2026-33683MEDIUMCVSS 5.4EG 5.42026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "about" field allows any registered user to inject arbitrary JavaScript that executes when othe…
- CVE-2026-33684MEDIUMCVSS 5.3EG 5.3✓ Fixed in 29.02026-06-22
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions d…
- CVE-2026-33685MEDIUMCVSS 5.3EG 5.32026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no authentication or authorization checks, allowing any unauthenticated attacker to extract ad ca…
- CVE-2026-33688MEDIUMCVSS 5.3EG 5.32026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allow…
- CVE-2026-33690MEDIUMCVSS 5.3EG 5.32026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client's IP address. An attacker can spoof t…
- CVE-2026-33692HIGHCVSS 7.5EG 7.5✓ Fixed in 29.02026-06-22
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as …
- CVE-2026-33716CRITICALCVSS 9.4EG 9.42026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that override…
- CVE-2026-33717HIGHCVSS 8.8EG 8.82026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a web-accessible temporary directory using the or…
- CVE-2026-33719HIGHCVSS 8.6EG 8.62026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disable.json.php` use key-based authentication with an empty string default key. When…
- CVE-2026-33723HIGHCVSS 6.5EG 7.12026-03-23
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concatenates the `$this->users_id` property directly into an INSERT SQL query without sanitizatio…
- CVE-2026-33731MEDIUMCVSS 6.5EG 6.5✓ Fixed in 29.02026-06-22
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that allows an attacker to forge webhook requests with a…
- CVE-2026-33759MEDIUMCVSS 5.3EG 5.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any authentication or authorization check. Pr…
- CVE-2026-33761MEDIUMCVSS 5.3EG 5.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any authentication check, while every other endpoint in the same plugin directories (`add.json…
- CVE-2026-33763MEDIUMCVSS 5.3EG 5.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given password is correct for any password-protect…
- CVE-2026-33764MEDIUMCVSS 4.3EG 4.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endpoint loads AI response objects using an attacker-controlled `$_REQUEST['id']` parameter without validating that the AI …
- CVE-2026-33766MEDIUMCVSS 6.5EG 6.52026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP ranges before fetching, but `url_get_contents()` follows HTTP redirects without re-validating …
- CVE-2026-33767HIGHCVSS 8.8EG 8.8✓ Fixed in 26.02026-03-27
vulnerable: 10.4 ... 25.0 (16 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using a prepared statement placeholder (`?`) for `users_id` but directly concatenates …
- CVE-2026-33770CRITICALCVSS 9.8EG 9.82026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` constructs a SQL SELECT query by directly interpolating both `$clean_title` and `$id` into th…
- CVE-2026-33867HIGHCVSS 7.5EG 7.52026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or e…
- CVE-2026-34245MEDIUMCVSS 6.3EG 6.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast…
- CVE-2026-34247MEDIUMCVSS 5.4EG 5.42026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbit…
- CVE-2026-34362MEDIUMCVSS 5.4EG 5.42026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never ex…
- CVE-2026-34364MEDIUMCVSS 5.3EG 5.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access controls on categories. In the default …
- CVE-2026-34368MEDIUMCVSS 5.3EG 5.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sende…
- CVE-2026-34369MEDIUMCVSS 5.3EG 5.32026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-prote…
- CVE-2026-34375HIGHCVSS 8.2EG 8.22026-03-27
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any encoding or sanitiza…
- CVE-2026-34394HIGHCVSS 8.1EG 8.12026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's admin plugin configuration endpoint (admin/save.json.php) lacks any CSRF token validation. There is no call to isGlobalTokenValid() or verifyToken() before …
- CVE-2026-34395MEDIUMCVSS 6.5EG 6.52026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpo…
- CVE-2026-34396MEDIUMCVSS 6.1EG 6.12026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms without applying htmlspecialchars() or any other output encoding. The jsonToFormElements() f…
- CVE-2026-34611MEDIUMCVSS 6.5EG 6.52026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies ad…
- CVE-2026-34613MEDIUMCVSS 6.5EG 6.52026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session bu…
- CVE-2026-34716MEDIUMCVSS 6.4EG 6.42026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the hea…
- CVE-2026-34731HIGHCVSS 7.5EG 7.52026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthenticated users to terminate any active live stream. The endpoint processes RTMP callback eve…
- CVE-2026-34732HIGHCVSS 7.5EG 7.52026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.…
- CVE-2026-34733HIGHCVSS 7.3EG 7.32026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run ex…
- CVE-2026-34737MEDIUMCVSS 6.5EG 6.52026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-sty…
- CVE-2026-34738MEDIUMCVSS 4.3EG 4.32026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active…
- CVE-2026-34739MEDIUMCVSS 6.1EG 6.12026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other out…
- CVE-2026-34740MEDIUMCVSS 6.5EG 6.52026-03-31
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every…
- CVE-2026-35179MEDIUMCVSS 5.3EG 5.32026-04-06
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint …
- CVE-2026-35181MEDIUMCVSS 4.3EG 4.32026-04-06
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-b…
- CVE-2026-35448LOWCVSS 3.7EG 3.72026-04-06
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an …
- CVE-2026-35449MEDIUMCVSS 5.3EG 5.32026-04-06
vulnerable: 10.4 ... 26.0 (17 versions)
WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after ins…
Check whether wwbn/avideo is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for wwbn/avideo CVEs against the assets you own.
Start Free Scan →