Wwbn
Wwbn Avideo: vulnerabilidades y CVE
Wwbn Avideo tiene 345 vulnerabilidades publicadas, 290 de ellas en los últimos 12 meses. 47 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE345
Últimos 12 meses290
Críticas47
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100630 | Media (5.1) | 0.18% | — | 26 sept 2026 | AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML… |
| CVE-2026-92915 | Media (6.9) | 0.42% | — | 17 sept 2026 | WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] =… |
| CVE-2026-92914 | Alta (8.6) | 0.47% | — | 17 sept 2026 | AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with… |
| CVE-2026-92913 | Crítica (9.1) | 0.53% | — | 17 sept 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number generator when creating account activation / login pairing codes. getRandomCode() in… |
| CVE-2026-92912 | Alta (8.3) | 0.30% | — | 17 sept 2026 | AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation… |
| CVE-2026-92586 | Media (5.3) | 0.26% | — | 16 sept 2026 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and… |
| CVE-2026-92585 | Media (5.3) | 0.26% | — | 16 sept 2026 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted… |
| CVE-2026-92584 | Media (5.3) | 0.26% | — | 16 sept 2026 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which… |
| CVE-2026-92583 | Media (6.9) | 0.30% | — | 16 sept 2026 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force… |
| CVE-2026-92582 | Alta (7.1) | 0.18% | — | 16 sept 2026 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the… |
| CVE-2026-92581 | Media (5.3) | 0.29% | — | 16 sept 2026 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can… |
| CVE-2026-92580 | Alta (8.7) | 1.4% | — | 16 sept 2026 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p… |
| CVE-2026-92579 | Media (5.3) | 0.27% | — | 16 sept 2026 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The… |
| CVE-2026-92578 | Crítica (9.2) | 0.62% | — | 16 sept 2026 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and… |
| CVE-2026-92577 | Alta (8.7) | 0.43% | — | 16 sept 2026 | In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers… |
| CVE-2026-91967 | Media (5.3) | 0.34% | — | 15 sept 2026 | AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with… |
| CVE-2026-91965 | Alta (8.7) | 0.45% | — | 15 sept 2026 | WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission… |
| CVE-2026-91966 | Media (6.9) | 0.40% | — | 15 sept 2026 | AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to… |
| CVE-2026-90552 | Media (5.3) | 0.36% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and… |
| CVE-2026-90550 | Media (6.9) | 0.41% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can… |
| CVE-2026-90549 | Media (6.9) | 0.34% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with… |
| CVE-2026-90548 | Media (6.9) | 0.40% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can… |
| CVE-2026-90547 | Media (6.9) | 0.41% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from… |
| CVE-2026-90545 | Media (5.3) | 0.29% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected… |
| CVE-2026-90544 | Media (5.3) | 0.26% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can… |
| CVE-2026-90543 | Media (6.9) | 0.60% | — | 12 sept 2026 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads… |
| CVE-2026-90542 | Media (5.3) | 0.24% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create… |
| CVE-2026-90540 | Media (5.3) | 0.26% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add… |
| CVE-2026-90539 | Media (6.9) | 0.41% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read… |
| CVE-2026-90538 | Media (6.9) | 0.36% | — | 12 sept 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.