WWBN AVideo是WWBN团队的一个由PHP编写的视频平台建站系统。 WWBN AVideo 26.0及之前版本存在代码问题漏洞,该漏洞源于EPG链接功能缺少SSRF防护,可能导致存储型服务端请求伪造攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34394 | 8.1 HIGH | AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking |
| CVE-2026-34731 | 7.5 HIGH | AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php |
| CVE-2026-34395 | 6.5 MEDIUM | AVideo: Mass User PII Disclosure via Missing Authorization in YPTWallet users.json.php |
| CVE-2026-34613 | 6.5 MEDIUM | AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins |
| CVE-2026-34737 | 6.5 MEDIUM | AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscrip |
| CVE-2026-34611 | 6.5 MEDIUM | AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users |
| CVE-2026-34733 | 6.5 MEDIUM | AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard |
| CVE-2026-34716 | 6.4 MEDIUM | AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification |
| CVE-2026-34739 | 6.1 MEDIUM | AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php |
| CVE-2026-34396 | 6.1 MEDIUM | AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel |
| CVE-2026-34732 | 5.3 MEDIUM | AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints |
| CVE-2026-34738 | 4.3 MEDIUM | AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter |
No comments yet