Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AVideo — Vulnerabilities & Security Advisories 199

All 199 CVE vulnerabilities found in AVideo, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting AVideo, an open-source video sharing platform developed by Attila Lugosi, categorized under common weakness types such as cross-site scripting, SQL injection, and server-side request forgery. The collection aggregates known defects reported between 2016 and 2024, providing a chronological view of security incidents impacting this specific software ecosystem. Users can utilize this resource to track vendor advisories for AVideo, gaining insight into how issues were disclosed and patched over time. It also serves as a reference for understanding the prevalence and nature of specific weakness classes within video management applications. By examining the vulnerability history, developers and security professionals can identify recurring patterns in the codebase and assess the overall security posture of the product. The data highlights critical areas where the application may be susceptible to exploitation, aiding in risk assessment and remediation planning. This compilation aims to enhance transparency and support informed decision-making regarding the deployment and maintenance of AVideo instances. It offers a structured overview of past incidents without promoting any commercial intent, focusing solely on factual security information. The page is designed to be a neutral archive for researchers, auditors, and administrators who need to evaluate the impact of known flaws on their systems.

Vendor: WWBN

CVE IDTitleCVSSSeverityPublished
CVE-2026-60092 AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel CWE-79 6.1 Medium2026-07-08
CVE-2026-56347 AVideo TopMenu Plugin - Stored Cross-Site Scripting via Unescaped Menu Item Fields CWE-79 6.1 Medium2026-06-20
CVE-2026-56346 AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint CWE-306 6.5 Medium2026-06-20
CVE-2026-56345 AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint CWE-287 8.1 High2026-06-20
CVE-2026-56342 AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter CWE-918 6.8 Medium2026-06-20
CVE-2026-56341 AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php CWE-862 7.5 High2026-06-20
CVE-2026-45580 WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute CWE-79 5.4 Medium2026-05-29
CVE-2026-45578 WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL CWE-78 8.8 High2026-05-29
CVE-2026-45610 WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA CWE-306 5.7 Medium2026-05-29
CVE-2026-45619 AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post CWE-367 6.5 Medium2026-05-29
CVE-2026-45620 AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration CWE-204 5.3 Medium2026-05-29
CVE-2026-45731 WWBN AVideo: Authenticated Arbitrary File Read in view/update.php CWE-22--2026-05-29
CVE-2026-46337 WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php` CWE-22--2026-05-29
CVE-2026-47694 WWBN AVideo: Stored XSS via unescaped Gallery category description CWE-79 5.4 Medium2026-05-29
CVE-2026-47696 WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint CWE-345--2026-05-29
CVE-2026-43885 WWBN AVideo: Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization CWE-200--2026-05-11
CVE-2026-43884 WWBN AVideo: SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL() CWE-918 7.7 High2026-05-11
CVE-2026-43883 WWBN AVideo: IDOR in PayPalYPT agreementCancel.json.php Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements CWE-639 4.2 Medium2026-05-11
CVE-2026-43882 WWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing CWE-93 4.3 Medium2026-05-11
CVE-2026-43881 WWBN AVideo: Unauthenticated User Enumeration in `objects/users.json.php` via `isCompany` Parameter Flips `$ignoreAdmin = true` and Defeats Admin-Only Listing Guard CWE-306 5.3 Medium2026-05-11
CVE-2026-43880 WWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From Address CWE-940 5.3 Medium2026-05-11
CVE-2026-43879 WWBN AVideo: Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass CWE-918 5.4 Medium2026-05-11
CVE-2026-43878 WWBN AVideo: Reflected XSS in plugin/Meet/iframe.php via Unescaped `user`/`pass` Parameters Reflected into JavaScript String Literal CWE-79 6.1 Medium2026-05-11
CVE-2026-43877 WWBN AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Any Logged-in User's Profile Photo with Arbitrary Bytes CWE-352 5.4 Medium2026-05-11
CVE-2026-43876 WWBN AVideo: HTML Injection in notifySubscribers.json.php Enables Platform-Branded Phishing Emails to Channel Subscribers CWE-79 6.4 Medium2026-05-11
CVE-2026-43875 WWBN AVideo: Password Hash Leaked in MobileManager OAuth Redirect URL Enables Account Takeover CWE-598 6.8 Medium2026-05-11
CVE-2026-43873 WWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server CWE-209 7.5 High2026-05-11
CVE-2026-43874 WWBN AVideo: Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass CWE-94 7.2 High2026-05-11
CVE-2026-41304 WWBN AVideo vulnerable to RCE caused by clonesite plugin CWE-77 8.8AIHighAI2026-04-21
CVE-2026-41064 AVideo has an incomplete fix for CVE-2026-33502 (Command Injection) CWE-78 9.3 Critical2026-04-21

All 199 known CVE vulnerabilities affecting AVideo with full Chinese analysis, references, and POCs where available.