WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在安全漏洞,该漏洞源于plugin/YPTWallet/view/users.json.php端点缺少管理员权限检查,可能导致任意认证用户泄露完整用户数据库。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34394 | 8.1 HIGH | AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking |
| CVE-2026-34731 | 7.5 HIGH | AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php |
| CVE-2026-34613 | 6.5 MEDIUM | AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins |
| CVE-2026-34737 | 6.5 MEDIUM | AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscrip |
| CVE-2026-34611 | 6.5 MEDIUM | AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users |
| CVE-2026-34740 | 6.5 MEDIUM | AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation |
| CVE-2026-34733 | 6.5 MEDIUM | AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard |
| CVE-2026-34716 | 6.4 MEDIUM | AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification |
| CVE-2026-34739 | 6.1 MEDIUM | AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php |
| CVE-2026-34396 | 6.1 MEDIUM | AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel |
| CVE-2026-34732 | 5.3 MEDIUM | AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints |
| CVE-2026-34738 | 4.3 MEDIUM | AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter |
No comments yet