« Volver al listado

Wwbn

Wwbn Avideo: vulnerabilidades y CVE

Wwbn Avideo tiene 345 vulnerabilidades publicadas, 290 de ellas en los últimos 12 meses. 47 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE345
Últimos 12 meses290
Críticas47
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-100630Media (5.1)0.18%—26 sept 2026
AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML…
CVE-2026-92915Media (6.9)0.42%—17 sept 2026
WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] =…
CVE-2026-92914Alta (8.6)0.47%—17 sept 2026
AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with…
CVE-2026-92913Crítica (9.1)0.53%—17 sept 2026
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in…
CVE-2026-92912Alta (8.3)0.30%—17 sept 2026
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation…
CVE-2026-92586Media (5.3)0.26%—16 sept 2026
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and…
CVE-2026-92585Media (5.3)0.26%—16 sept 2026
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted…
CVE-2026-92584Media (5.3)0.26%—16 sept 2026
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which…
CVE-2026-92583Media (6.9)0.30%—16 sept 2026
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force…
CVE-2026-92582Alta (7.1)0.18%—16 sept 2026
AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the…
CVE-2026-92581Media (5.3)0.29%—16 sept 2026
In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can…
CVE-2026-92580Alta (8.7)1.4%—16 sept 2026
In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p…
CVE-2026-92579Media (5.3)0.27%—16 sept 2026
In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The…
CVE-2026-92578Crítica (9.2)0.62%—16 sept 2026
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and…
CVE-2026-92577Alta (8.7)0.43%—16 sept 2026
In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers…
CVE-2026-91967Media (5.3)0.34%—15 sept 2026
AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with…
CVE-2026-91965Alta (8.7)0.45%—15 sept 2026
WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission…
CVE-2026-91966Media (6.9)0.40%—15 sept 2026
AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to…
CVE-2026-90552Media (5.3)0.36%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and…
CVE-2026-90550Media (6.9)0.41%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can…
CVE-2026-90549Media (6.9)0.34%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with…
CVE-2026-90548Media (6.9)0.40%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can…
CVE-2026-90547Media (6.9)0.41%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from…
CVE-2026-90545Media (5.3)0.29%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected…
CVE-2026-90544Media (5.3)0.26%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can…
CVE-2026-90543Media (6.9)0.60%—12 sept 2026
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads…
CVE-2026-90542Media (5.3)0.24%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create…
CVE-2026-90540Media (5.3)0.26%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add…
CVE-2026-90539Media (6.9)0.41%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read…
CVE-2026-90538Media (6.9)0.36%—12 sept 2026
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application68
  2. T1210 Exploitation of Remote Services37
  3. T1005 Data from Local System26
  4. T1189 Drive-by Compromise23
  5. T1059.007 JavaScript18
  6. T1078 Valid Accounts18

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Wwbn