Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avideo MEDIUM 5.4
CVE-2026-47694

WWBN AVideo is an open source video platform. In 29.0 and earlier, AVideo stores category descriptions from user input and later renders category_des…

Fix: after 29.0
Fix from $1,600 2026-05-29
Avideo MEDIUM 5.3
CVE-2026-45620

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an e…

Fix: after 29.0
Fix from $1,600 2026-05-29
Avideo MEDIUM 5.3
CVE-2026-46337

WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk…

Fix: after 29.0
Fix from $1,600 2026-05-29
Avideo HIGH 8.8
CVE-2026-45578

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branc…

Fix: after 29.0
Fix from $1,950 2026-05-29
Avideo MEDIUM 6.5
CVE-2026-45610

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/Logi…

Fix: after 29.0
Fix from $1,600 2026-05-29
Avideo MEDIUM 6.5
CVE-2026-45619

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the…

Fix: after 29.0
Fix from $1,600 2026-05-29
Avideo MEDIUM 5.4
CVE-2026-45580

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-s…

Fix: after 29.0
Fix from $1,600 2026-05-29
Avideo CRITICAL 9.8
CVE-2026-41304

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shel…

Fix: after 29.0
Fix from $2,300 2026-04-22
Avideo CRITICAL 9.3
CVE-2026-41064

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` f…

Fix: after 29.0
Fix from $2,300 2026-04-22
Avideo HIGH 8.1
CVE-2026-41058

WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not a…

Fix: after 29.0
Fix from $1,950 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-41060

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-d…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-41062

WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVi…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.4
CVE-2026-41061

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.4
CVE-2026-41063

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides …

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo HIGH 8.1
CVE-2026-41056

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in `objects/functions.php` refle…

Fix: after 29.0
Fix from $1,950 2026-04-21
Avideo HIGH 7.1
CVE-2026-40926

WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objec…

Fix: after 29.0
Fix from $1,950 2026-04-21
Avideo HIGH 7.1
CVE-2026-41057

WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two sep…

Fix: after 29.0
Fix from $1,950 2026-04-21
Avideo MEDIUM 5.4
CVE-2026-40928

WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` accept state-changing reque…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.4
CVE-2026-40929

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mutating JSON endpoint that del…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.3
CVE-2026-40935

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from th…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.3
CVE-2026-41055

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` v…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo CRITICAL 10.0
CVE-2026-40911

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON messa…

Fix: after 29.0
Fix from $2,300 2026-04-21
Avideo HIGH 8.3
CVE-2026-40925

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) pe…

Fix: after 29.0
Fix from $1,950 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-40907

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an In…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 6.5
CVE-2026-40909

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by dire…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo MEDIUM 5.3
CVE-2026-40908

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns t…

Fix: after 29.0
Fix from $1,600 2026-04-21
Avideo HIGH 7.6
CVE-2026-39369

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploade…

Fix: after 26.0
Fix from $1,950 2026-04-07
Avideo HIGH 7.1
CVE-2026-39370

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL…

Fix: after 26.0
Fix from $1,950 2026-04-07
Avideo MEDIUM 6.5
CVE-2026-39366

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction ded…

Fix: after 26.0
Fix from $1,600 2026-04-07
Avideo MEDIUM 6.5
CVE-2026-39368

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restrea…

Fix: after 26.0
Fix from $1,600 2026-04-07