Wwbn Avideo Vulnerabilities

10 advisories affecting Wwbn Avideo

10

Total CVEs

8

Critical

2

High

CVE-2026-41064

Apr 22, 2026

Critical (9.3)

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `cur...

Read Advisory

CVE-2026-40911

Apr 21, 2026

Critical (10.0)

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without sanitiz...

Read Advisory

CVE-2026-33297

Mar 23, 2026

Critical (9.1)

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due t...

Read Advisory

CVE-2026-33351

Mar 23, 2026

Critical (9.1)

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live p...

Read Advisory

CVE-2026-33352

Mar 23, 2026

Critical (9.8)

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowC...

Read Advisory

CVE-2026-33478

Mar 23, 2026

Critical (10.0)

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker ...

Read Advisory

CVE-2026-33502

Mar 23, 2026

Critical (9.3)

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to mak...

Read Advisory

CVE-2026-33716

Mar 23, 2026

Critical (9.4)

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplie...

Read Advisory

CVE-2026-33292

Mar 22, 2026

High (7.5)

WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to str...

Read Advisory

CVE-2026-33293

Mar 22, 2026

High (8.1)

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitizatio...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.