WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在安全漏洞,该漏洞源于Scheduler插件中的三个list.json.php端点缺乏身份验证检查,可能导致未经验证的攻击者检索所有计划任务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34374 | 9.1 CRITICAL | AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key |
| CVE-2026-34375 | 8.2 HIGH | AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Pa |
| CVE-2026-34245 | 6.3 MEDIUM | AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast H |
| CVE-2026-34247 | 5.4 MEDIUM | AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Liv |
| CVE-2026-34362 | 5.4 MEDIUM | AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTo |
| CVE-2026-33759 | 5.3 MEDIUM | AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents |
| CVE-2026-33763 | 5.3 MEDIUM | AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited |
| CVE-2026-34364 | 5.3 MEDIUM | AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Fi |
| CVE-2026-34368 | 5.3 MEDIUM | AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBala |
| CVE-2026-34369 | 5.3 MEDIUM | AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sour |
| CVE-2026-33764 | 4.3 MEDIUM | AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcrip |
| CVE-2026-33766 | AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints | |
| CVE-2026-33767 | AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly | |
| CVE-2026-33770 | AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title a | |
| CVE-2026-33867 | AVideo has Plaintext Video Password Storage |
No comments yet