WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在访问控制错误漏洞,该漏洞源于CreatePlugin模板中的list.json.php端点缺少身份验证,可能导致未经身份验证的数据泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34394 | 8.1 HIGH | AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking |
| CVE-2026-34731 | 7.5 HIGH | AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php |
| CVE-2026-34395 | 6.5 MEDIUM | AVideo: Mass User PII Disclosure via Missing Authorization in YPTWallet users.json.php |
| CVE-2026-34613 | 6.5 MEDIUM | AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins |
| CVE-2026-34737 | 6.5 MEDIUM | AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscrip |
| CVE-2026-34611 | 6.5 MEDIUM | AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users |
| CVE-2026-34740 | 6.5 MEDIUM | AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation |
| CVE-2026-34733 | 6.5 MEDIUM | AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard |
| CVE-2026-34716 | 6.4 MEDIUM | AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification |
| CVE-2026-34739 | 6.1 MEDIUM | AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php |
| CVE-2026-34396 | 6.1 MEDIUM | AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel |
| CVE-2026-34738 | 4.3 MEDIUM | AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter |
No comments yet