Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.41% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any authentication or authorization check. Private playlists (including `watch_later` and `favorite` types) are correctly… | |
| Analizada | Media (6.5) | 0.22% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concatenates the `$this->users_id` property directly into an INSERT SQL query without sanitization or parameterized binding. This property originates from `$_POST['user_id']` in… | |
| Analizada | Alta (8.6) | 0.49% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disable.json.php` use key-based authentication with an empty string default key. When the CDN plugin is enabled but the key has not been configured (the default… | |
| Analizada | Alta (8.8) | 0.55% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a web-accessible temporary directory using the original URL's filename and extension (including `.php`). By providing an invalid… | |
| Analizada | Crítica (9.4) | 0.57% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token verification requests. An attacker can redirect… | |
| Analizada | Media (5.3) | 0.27% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client's IP address. An attacker can spoof their IP address by sending forged headers, bypassing any IP-based access… | |
| Analizada | Media (5.3) | 0.37% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allows an unauthenticated attacker to enumerate valid usernames and determine whether… | |
| Analizada | Media (5.3) | 0.43% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no authentication or authorization checks, allowing any unauthenticated attacker to extract ad campaign analytics data including video titles, user channel names, user IDs, ad… | |
| Analizada | Media (5.4) | 0.25% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "about" field allows any registered user to inject arbitrary JavaScript that executes when other users visit their channel page. The `xss_esc()` function entity-encodes input… | |
| Analizada | Alta (7.2) | 0.64% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a `name` parameter via POST and passes it to `Plugin::getDatabaseFileName()` without any path traversal sanitization. This allows an authenticated admin (or an attacker… | |
| Analizada | Alta (8.8) | 0.50% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint passes `$_REQUEST['live_schedule_id']` through multiple functions without sanitization until it reaches `Scheduler_commands::getAllActiveOrToRepeat()`, which directly concatenates it into a SQL `LIKE`… | |
| Analizada | Alta (7.6) | 0.34% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privileges to perform full video management operations — including ownership transfer and deletion of any video — despite the permission being documented as only allowing video… | |
| Analizada | Alta (8.8) | 0.22% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts GET parameters for a state-changing operation that modifies user group permissions. The endpoint has no CSRF token validation, and the application explicitly sets… | |
| Analizada | Alta (8.8) | 0.92% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-controlled `users_id` and `liveTransmitionHistory_id` values from the JSON request body without any sanitization. This log file path is then concatenated directly… | |
| Analizada | Alta (8.8) | 0.84% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using `finfo` MIME type detection but derives the saved filename extension from the user-supplied original filename without an allowlist check. An attacker can… | |
| Analizada | Alta (7.5) | 0.72% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be included. In our test… | |
| Analizada | Alta (7.5) | 0.32% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued publicly (e.g., `view/url2Embed.json.php`), so any user can recover protected… | |
| Analizada | Alta (8.8) | 0.34% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting… | |
| Analizada | Alta (8.2) | 0.43% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to probe localhost/internal services and,… | |
| Analizada | Media (5.3) | 0.50% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated users to retrieve the complete permission matrix mapping user groups to plugins.… | |
| Analizada | Media (5.4) | 0.26% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `<a>` and `<img>` tags in comments, but explicitly disables Parsedown's `safeMode`. This creates a bypass:… | |
| Analizada | Media (6.1) | 0.27% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` parameter directly into an HTML `<input>` tag's attributes without any output encoding or sanitization. An attacker can craft a… | |
| Analizada | Alta (8.1) | 0.44% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `objects/listFiles.json.php`, which was hardened with a `realpath()` + directory… | |
| Analizada | Alta (7.3) | 0.42% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration bypass exists for specific blacklisted endpoints when the request… | |
| Analizada | Alta (8.1) | 0.32% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who obtains a target user's public key can factor the 512-bit RSA modulus… |