WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在安全漏洞,该漏洞源于plugin/Live/uploadPoster.php端点缺少所有权检查,可能导致经过身份验证的用户覆盖任意直播计划的海报图像并泄露广播密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34374 | 9.1 CRITICAL | AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key |
| CVE-2026-34375 | 8.2 HIGH | AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Pa |
| CVE-2026-34245 | 6.3 MEDIUM | AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast H |
| CVE-2026-34362 | 5.4 MEDIUM | AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTo |
| CVE-2026-33759 | 5.3 MEDIUM | AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents |
| CVE-2026-33763 | 5.3 MEDIUM | AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited |
| CVE-2026-33761 | 5.3 MEDIUM | AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email |
| CVE-2026-34364 | 5.3 MEDIUM | AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Fi |
| CVE-2026-34368 | 5.3 MEDIUM | AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBala |
| CVE-2026-34369 | 5.3 MEDIUM | AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sour |
| CVE-2026-33764 | 4.3 MEDIUM | AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcrip |
| CVE-2026-33766 | AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints | |
| CVE-2026-33767 | AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly | |
| CVE-2026-33770 | AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title a | |
| CVE-2026-33867 | AVideo has Plaintext Video Password Storage |
No comments yet