WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在访问控制错误漏洞,该漏洞源于Live插件中的on_publish_done.php端点缺少身份验证,可能导致未经身份验证的用户终止活动直播流。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34394 | 8.1 HIGH | AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking |
| CVE-2026-34395 | 6.5 MEDIUM | AVideo: Mass User PII Disclosure via Missing Authorization in YPTWallet users.json.php |
| CVE-2026-34613 | 6.5 MEDIUM | AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins |
| CVE-2026-34737 | 6.5 MEDIUM | AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscrip |
| CVE-2026-34611 | 6.5 MEDIUM | AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users |
| CVE-2026-34740 | 6.5 MEDIUM | AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation |
| CVE-2026-34733 | 6.5 MEDIUM | AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard |
| CVE-2026-34716 | 6.4 MEDIUM | AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification |
| CVE-2026-34739 | 6.1 MEDIUM | AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php |
| CVE-2026-34396 | 6.1 MEDIUM | AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel |
| CVE-2026-34732 | 5.3 MEDIUM | AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints |
| CVE-2026-34738 | 4.3 MEDIUM | AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter |
No comments yet