Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-47694 WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_des… Avideo after 29.0 Fix from $1,6002026-05-29 MEDIUM 5.3 CVE-2026-45620 WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an e… Avideo after 29.0 Fix from $1,6002026-05-29 MEDIUM 5.3 CVE-2026-46337 WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk… Avideo after 29.0 Fix from $1,6002026-05-29 HIGH 8.8 CVE-2026-45578 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branc… Avideo after 29.0 Fix from $1,9502026-05-29 MEDIUM 6.5 CVE-2026-45610 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/Logi… Avideo after 29.0 Fix from $1,6002026-05-29 MEDIUM 6.5 CVE-2026-45619 WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the… Avideo after 29.0 Fix from $1,6002026-05-29 MEDIUM 5.4 CVE-2026-45580 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-s… Avideo after 29.0 Fix from $1,6002026-05-29 CRITICAL 9.8 CVE-2026-41304 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shel… Avideo after 29.0 Fix from $2,3002026-04-22 CRITICAL 9.3 CVE-2026-41064 WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` f… Avideo after 29.0 Fix from $2,3002026-04-22 HIGH 8.1 CVE-2026-41058 WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not a… Avideo after 29.0 Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-41060 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-d… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-41062 WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVi… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-41061 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-41063 WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides … Avideo after 29.0 Fix from $1,6002026-04-21 HIGH 8.1 CVE-2026-41056 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in `objects/functions.php` refle… Avideo after 29.0 Fix from $1,9502026-04-21 HIGH 7.1 CVE-2026-40926 WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objec… Avideo after 29.0 Fix from $1,9502026-04-21 HIGH 7.1 CVE-2026-41057 WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two sep… Avideo after 29.0 Fix from $1,9502026-04-21 MEDIUM 5.4 CVE-2026-40928 WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` accept state-changing reque… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-40929 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mutating JSON endpoint that del… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-40935 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from th… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-41055 WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` v… Avideo after 29.0 Fix from $1,6002026-04-21 CRITICAL 10.0 CVE-2026-40911 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON messa… Avideo after 29.0 Fix from $2,3002026-04-21 HIGH 8.3 CVE-2026-40925 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) pe… Avideo after 29.0 Fix from $1,9502026-04-21 MEDIUM 6.5 CVE-2026-40907 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an In… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-40909 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by dire… Avideo after 29.0 Fix from $1,6002026-04-21 MEDIUM 5.3 CVE-2026-40908 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns t… Avideo after 29.0 Fix from $1,6002026-04-21 HIGH 7.6 CVE-2026-39369 WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploade… Avideo after 26.0 Fix from $1,9502026-04-07 HIGH 7.1 CVE-2026-39370 WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL… Avideo after 26.0 Fix from $1,9502026-04-07 MEDIUM 6.5 CVE-2026-39366 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction ded… Avideo after 26.0 Fix from $1,6002026-04-07 MEDIUM 6.5 CVE-2026-39368 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restrea… Avideo after 26.0 Fix from $1,6002026-04-07