WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在授权问题漏洞,该漏洞源于会话ID固定和会话再生绕过,可能导致会话劫持攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33478 | 10.0 CRITICAL | AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, |
| CVE-2026-33352 | 9.8 CRITICAL | AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escap |
| CVE-2026-33716 | 9.4 CRITICAL | AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in c |
| CVE-2026-33502 | 9.3 CRITICAL | AVideo has Unauthenticated SSRF via plugin/Live/test.php |
| CVE-2026-33351 | 9.1 CRITICAL | AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaini |
| CVE-2026-33507 | 8.8 HIGH | AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Exec |
| CVE-2026-33717 | 8.8 HIGH | AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloa |
| CVE-2026-33648 | 8.8 HIGH | AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionH |
| CVE-2026-33647 | 8.8 HIGH | AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery Fil |
| CVE-2026-33479 | 8.8 HIGH | AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through |
| CVE-2026-33719 | 8.6 HIGH | AVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypa |
| CVE-2026-33513 | 8.6 HIGH | AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writab |
| CVE-2026-33480 | 8.6 HIGH | AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated Live |
| CVE-2026-33651 | 8.1 HIGH | AVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_i |
| CVE-2026-33482 | 8.1 HIGH | AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegComm |
| CVE-2026-33649 | 8.1 HIGH | AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitra |
| CVE-2026-33354 | 7.6 HIGH | AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `a |
| CVE-2026-33650 | 7.6 HIGH | AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Vid |
| CVE-2026-33485 | 7.5 HIGH | AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream N |
| CVE-2026-33483 | 7.5 HIGH | AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet