Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AVideo — Vulnerabilities & Security Advisories 213

All 213 CVE vulnerabilities found in AVideo, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting AVideo, an open-source video sharing platform, categorized by common weakness enumeration types and associated tags. It aggregates a comprehensive collection of known flaws identified in the software, ranging from critical remote code execution risks to minor information disclosure issues. The dataset covers historical vulnerability data spanning from the initial releases of the software through the most recent updates, ensuring a chronological view of the product's security posture over time. Users can utilize this resource to track vendor advisories and security announcements related to AVideo, gaining insight into how the development team addresses reported issues and patches identified weaknesses. Additionally, the page allows for a deeper understanding of specific weakness classes by providing detailed descriptions and technical context for each vulnerability type, helping security professionals assess the nature and severity of potential threats. Visitors can also look up a product's vulnerability history to observe trends in vulnerability discovery and resolution, facilitating better risk management and informed decision-making regarding software adoption and maintenance. This information serves as a valuable reference for developers, system administrators, and security researchers seeking to understand the historical and current security landscape of the AVideo platform without relying on marketing language or specific CVE identifiers.

Vendor: WWBN

CVE IDTitleCVSSSeverityPublished
CVE-2026-72748 AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php CWE-306 9.1 Critical2026-08-11
CVE-2026-72747 AVideo Stored Cross-Site Scripting via Unauthenticated Registration CWE-79 7.2 High2026-08-11
CVE-2026-64626 AVideo Encoder downloadURL SSRF via unpinned retry fallback CWE-918 6.4 Medium2026-07-20
CVE-2026-64625 AVideo before 29.0 OS Command Injection via execAsync CWE-78 9.8 Critical2026-07-20
CVE-2026-33731 AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data CWE-345 6.5 Medium2026-07-16
CVE-2026-55173 AVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink CWE-78 8.1 High2026-07-16
CVE-2026-33692 AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration CWE-20 7.5 High2026-07-16
CVE-2026-63305 AVideo through 29.0 OS Command Injection via ffmpeg.json.php CWE-78 8.1 High2026-07-16
CVE-2026-63304 AVideo through 29.0 OS Command Injection via listFFmpegProcesses CWE-78 8.1 High2026-07-16
CVE-2026-54458 AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin CWE-79 9.6 Critical2026-07-15
CVE-2026-50183 WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section CWE-79 4.7 Medium2026-07-15
CVE-2026-50182 AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Gallery Pagination CWE-79 6.1 Medium2026-07-15
CVE-2026-49279 WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass) CWE-79--2026-07-15
CVE-2026-33684 AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions CWE-862 5.3 Medium2026-07-15
CVE-2026-60092 AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel CWE-79 6.1 Medium2026-07-08
CVE-2026-56347 AVideo TopMenu Plugin - Stored Cross-Site Scripting via Unescaped Menu Item Fields CWE-79 6.1 Medium2026-06-20
CVE-2026-56346 AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint CWE-306 6.5 Medium2026-06-20
CVE-2026-56345 AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint CWE-287 8.1 High2026-06-20
CVE-2026-56342 AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter CWE-918 6.8 Medium2026-06-20
CVE-2026-56341 AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php CWE-862 7.5 High2026-06-20
CVE-2026-45580 WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute CWE-79 5.4 Medium2026-05-29
CVE-2026-45578 WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL CWE-78 8.8 High2026-05-29
CVE-2026-45610 WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA CWE-306 5.7 Medium2026-05-29
CVE-2026-45619 AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post CWE-367 6.5 Medium2026-05-29
CVE-2026-45620 AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration CWE-204 5.3 Medium2026-05-29
CVE-2026-45731 WWBN AVideo: Authenticated Arbitrary File Read in view/update.php CWE-22--2026-05-29
CVE-2026-46337 WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php` CWE-22--2026-05-29
CVE-2026-47694 WWBN AVideo: Stored XSS via unescaped Gallery category description CWE-79 5.4 Medium2026-05-29
CVE-2026-47696 WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint CWE-345--2026-05-29
CVE-2026-43885 WWBN AVideo: Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization CWE-200--2026-05-11

All 213 known CVE vulnerabilities affecting AVideo with full Chinese analysis, references, and POCs where available.