Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AVideo — Vulnerabilities & Security Advisories 213

All 213 CVE vulnerabilities found in AVideo, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting AVideo, an open-source video sharing platform, categorized by common weakness enumeration types and associated tags. It aggregates a comprehensive collection of known flaws identified in the software, ranging from critical remote code execution risks to minor information disclosure issues. The dataset covers historical vulnerability data spanning from the initial releases of the software through the most recent updates, ensuring a chronological view of the product's security posture over time. Users can utilize this resource to track vendor advisories and security announcements related to AVideo, gaining insight into how the development team addresses reported issues and patches identified weaknesses. Additionally, the page allows for a deeper understanding of specific weakness classes by providing detailed descriptions and technical context for each vulnerability type, helping security professionals assess the nature and severity of potential threats. Visitors can also look up a product's vulnerability history to observe trends in vulnerability discovery and resolution, facilitating better risk management and informed decision-making regarding software adoption and maintenance. This information serves as a valuable reference for developers, system administrators, and security researchers seeking to understand the historical and current security landscape of the AVideo platform without relying on marketing language or specific CVE identifiers.

Vendor: WWBN

CVE IDTitleCVSSSeverityPublished
CVE-2026-43884 WWBN AVideo: SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL() CWE-918 7.7 High2026-05-11
CVE-2026-43883 WWBN AVideo: IDOR in PayPalYPT agreementCancel.json.php Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements CWE-639 4.2 Medium2026-05-11
CVE-2026-43882 WWBN AVideo: Unauthenticated CRLF/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing CWE-93 4.3 Medium2026-05-11
CVE-2026-43881 WWBN AVideo: Unauthenticated User Enumeration in `objects/users.json.php` via `isCompany` Parameter Flips `$ignoreAdmin = true` and Defeats Admin-Only Listing Guard CWE-306 5.3 Medium2026-05-11
CVE-2026-43880 WWBN AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Allows Phishing from Site's Legitimate From Address CWE-940 5.3 Medium2026-05-11
CVE-2026-43879 WWBN AVideo: Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass CWE-918 5.4 Medium2026-05-11
CVE-2026-43878 WWBN AVideo: Reflected XSS in plugin/Meet/iframe.php via Unescaped `user`/`pass` Parameters Reflected into JavaScript String Literal CWE-79 6.1 Medium2026-05-11
CVE-2026-43877 WWBN AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Any Logged-in User's Profile Photo with Arbitrary Bytes CWE-352 5.4 Medium2026-05-11
CVE-2026-43876 WWBN AVideo: HTML Injection in notifySubscribers.json.php Enables Platform-Branded Phishing Emails to Channel Subscribers CWE-79 6.4 Medium2026-05-11
CVE-2026-43875 WWBN AVideo: Password Hash Leaked in MobileManager OAuth Redirect URL Enables Account Takeover CWE-598 6.8 Medium2026-05-11
CVE-2026-43873 WWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server CWE-209 7.5 High2026-05-11
CVE-2026-43874 WWBN AVideo: Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass CWE-94 7.2 High2026-05-11
CVE-2026-41304 WWBN AVideo vulnerable to RCE caused by clonesite plugin CWE-77 8.8AIHighAI2026-04-21
CVE-2026-41064 AVideo has an incomplete fix for CVE-2026-33502 (Command Injection) CWE-78 9.3 Critical2026-04-21
CVE-2026-41063 WWBN AVideo has incomplete fix for CVE-2026-33500 (XSS) CWE-79 5.4 Medium2026-04-21
CVE-2026-41062 WWBN/AVideo has an incomplete fix for a directory traversal bypass via query string in ReceiveImage downloadURL parameters CWE-22 6.5 Medium2026-04-21
CVE-2026-41061 WWBN AVideo Vulnerable to stored XSS via Unanchored Duration Regex in Video Encoder Receiver CWE-79 5.4 Medium2026-04-21
CVE-2026-41060 AVideo's SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL CWE-918 7.7 High2026-04-21
CVE-2026-41058 AVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideo CWE-22 8.1 High2026-04-21
CVE-2026-41057 AVideo has CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) that Exposes Authenticated API Responses CWE-346 7.1 High2026-04-21
CVE-2026-41056 AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover CWE-942 8.1 High2026-04-21
CVE-2026-41055 AVideo has an incomplete fix for CVE-2026-33039 (SSRF) CWE-918 8.6 High2026-04-21
CVE-2026-40935 WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure CWE-804 5.3 Medium2026-04-21
CVE-2026-40929 WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators CWE-352 5.4 Medium2026-04-21
CVE-2026-40928 AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion CWE-352 5.4 Medium2026-04-21
CVE-2026-40926 WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script) CWE-352 7.1 High2026-04-21
CVE-2026-40925 WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials CWE-352 8.3 High2026-04-21
CVE-2026-40911 WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks CWE-94 10.0 Critical2026-04-21
CVE-2026-40909 WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE) CWE-22 8.7 High2026-04-21
CVE-2026-40908 WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php that Exposes Developer Emails and Deployed Version CWE-200 5.3 Medium2026-04-21

All 213 known CVE vulnerabilities affecting AVideo with full Chinese analysis, references, and POCs where available.