Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 491 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.55% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated directly into SQL queries in two locations —… | |
| Analizada | Alta (7.5) | 0.74% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An unauthenticated remote attacker can send arbitrary POST data which is written to… | |
| Analizada | Alta (8.1) | 4.7% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous shell metacharacters (`&&`, `;`, `|`, `` ` ``, `<`, `>`). However, it… | |
| Analizada | Alta (8.6) | 0.43% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IPv4-mapped IPv6 addresses (`::ffff:x.x.x.x`). The unauthenticated `plugin/LiveLinks/proxy.php` endpoint uses this function to validate URLs before fetching them with curl,… | |
| Analizada | Alta (8.8) | 0.73% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsanitized user input from `$_REQUEST['sections']` array values directly into PHP's `eval()` function. While the endpoint is gated behind `User::isAdmin()`, it has no CSRF token… | |
| Analizada | Crítica (10) | 11% | 💥 Exploit | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `clones.json.php` endpoint exposes clone secret keys without authentication,… | |
| Analizada | Media (6.5) | 0.35% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-controlled `chunkFile` parameter intended for staged upload chunks. Instead of restricting that path to trusted server-generated chunk locations, the endpoint accepts arbitrary… | |
| Analizada | Crítica (9.8) | 0.53% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShowCats` request parameter is sanitized only by stripping single-quote characters (`str_replace("'", '', ...)`), but this… | |
| Analizada | Crítica (9.1) | 0.54% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended configuration for this file), the `$_REQUEST['webSiteRootURL']`… | |
| Analizada | Media (5.1) | 0.47% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due to a logic error in how the submitted password value is processed, any password containing non-numeric characters is… | |
| Analizada | Alta (7.5) | 0.42% | — | Wwbn Avideo | 22/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, without sanitization via `escapeshellarg()`. If an attacker can… | |
| Analizada | Baja (2.1) | 0.26% | — | Wwbn Avideo | 22/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.location` assignment without JavaScript-safe encoding. After a user completes the… | |
| Analizada | Alta (8.2) | 0.25% | — | Wwbn Avideo | 22/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly into a JavaScript string literal without any escaping, allowing an… | |
| Analizada | Media (4.3) | 0.29% | — | Wwbn Avideo | 22/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other URL-fetching endpoints in AVideo that were hardened with… | |
| Analizada | Alta (8.1) | 0.57% | — | Wwbn Avideo | 22/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credentials can use path traversal sequences (e.g., `../../`) to delete arbitrary files… | |
| Analizada | Alta (7.5) | 0.56% | — | Wwbn Avideo | 22/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The `videoDirectory` GET parameter is used in two divergent code paths —… | |
| Modificada | Media (4.3) | 0.40% | — | Wwbn Avideo | 21/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob()` without restricting the path to an allowed base directory. An authenticated uploader can traverse the entire server filesystem by supplying arbitrary… | |
| Modificada | Media (5.5) | 0.41% | — | Wwbn Avideo | 21/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable `callbackURL` that is validated only by `isValidURL()` (URL format check). Unlike other AVideo endpoints that were… | |
| Analizada | Alta (8.1) | 0.39% | — | Wwbn Avideo | 20/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any unauthenticated request. The allowOrigin() function reflects any Origin header back in Access-Control-Allow-Origin with Access-Control-Allow-Credentials: true, enabling… | |
| Analizada | Media (5.3) | 0.36% | — | Wwbn Avideo | 20/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing algorithm to any unauthenticated user. An attacker can submit arbitrary passwords and receive their hashed equivalents, enabling offline password cracking against leaked… | |
| Analizada | Alta (8.6) | 0.46% | — | Wwbn Avideo | 20/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs against internal/private networks using isSSRFSafeURL(), but only checks the initial URL. When the initial URL responds with an HTTP redirect (Location header), the redirect… | |
| Analizada | Alta (8.1) | 0.52% | — | Wwbn Avideo | 20/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/checkConfiguration.php endpoint. install/checkConfiguration.php performs full application initialization: database setup, admin account creation, and configuration file… | |
| Analizada | Alta (8.1) | 0.73% | — | Wwbn Avideo | 20/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship with the admin password set to "password", which is automatically used to seed the admin account during installation, meaning any instance deployed without overriding… | |
| Analizada | Media (5.3) | 0.36% | — | Wwbn Avideo | 20/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser. User input from a URL parameter flows through PHP's json_encode() into a JavaScript function that renders it via… | |
| Analizada | Alta (8.6) | 0.47% | — | Wwbn Avideo-encoder | 20/3/2026 | 17/6/2026 | AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_POST['sort'] array keys are used directly as SQL column identifiers inside an ORDER BY clause. Although real_escape_string() was applied, it only escapes string-context… |