WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在代码问题漏洞,该漏洞源于url_get_contents()函数遵循HTTP重定向时未重新验证目标,可能导致绕过SSRF保护。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34374 | 9.1 CRITICAL | AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key |
| CVE-2026-34375 | 8.2 HIGH | AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Pa |
| CVE-2026-34245 | 6.3 MEDIUM | AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast H |
| CVE-2026-34247 | 5.4 MEDIUM | AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Liv |
| CVE-2026-34362 | 5.4 MEDIUM | AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTo |
| CVE-2026-33759 | 5.3 MEDIUM | AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents |
| CVE-2026-33761 | 5.3 MEDIUM | AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email |
| CVE-2026-33763 | 5.3 MEDIUM | AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited |
| CVE-2026-34364 | 5.3 MEDIUM | AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Fi |
| CVE-2026-34368 | 5.3 MEDIUM | AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBala |
| CVE-2026-34369 | 5.3 MEDIUM | AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sour |
| CVE-2026-33764 | 4.3 MEDIUM | AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcrip |
| CVE-2026-33767 | AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly | |
| CVE-2026-33770 | AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title a | |
| CVE-2026-33867 | AVideo has Plaintext Video Password Storage |
No comments yet