Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AVideo — Vulnerabilities & Security Advisories 220

All 220 CVE vulnerabilities found in AVideo, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting AVideo, an open-source video sharing platform, categorized by common weakness enumeration types and associated tags. It aggregates a comprehensive collection of known flaws identified in the software, ranging from critical remote code execution risks to minor information disclosure issues. The dataset covers historical vulnerability data spanning from the initial releases of the software through the most recent updates, ensuring a chronological view of the product's security posture over time. Users can utilize this resource to track vendor advisories and security announcements related to AVideo, gaining insight into how the development team addresses reported issues and patches identified weaknesses. Additionally, the page allows for a deeper understanding of specific weakness classes by providing detailed descriptions and technical context for each vulnerability type, helping security professionals assess the nature and severity of potential threats. Visitors can also look up a product's vulnerability history to observe trends in vulnerability discovery and resolution, facilitating better risk management and informed decision-making regarding software adoption and maintenance. This information serves as a valuable reference for developers, system administrators, and security researchers seeking to understand the historical and current security landscape of the AVideo platform without relying on marketing language or specific CVE identifiers.

Vendor: WWBN

CVE ID Title CVSS Severity Published
CVE-2026-40929 WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators CWE-352 5.4 Medium 2026-04-21
CVE-2026-40928 AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion CWE-352 5.4 Medium 2026-04-21
CVE-2026-40926 WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script) CWE-352 7.1 High 2026-04-21
CVE-2026-40925 WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials CWE-352 8.3 High 2026-04-21
CVE-2026-40911 WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks CWE-94 10.0 Critical 2026-04-21
CVE-2026-40909 WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE) CWE-22 8.7 High 2026-04-21
CVE-2026-40908 WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php that Exposes Developer Emails and Deployed Version CWE-200 5.3 Medium 2026-04-21
CVE-2026-40907 WWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens CWE-639 6.5 Medium 2026-04-21
CVE-2026-39370 WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732) CWE-918 7.1 High 2026-04-07
CVE-2026-39369 WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs CWE-22 7.6 High 2026-04-07
CVE-2026-39368 WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services CWE-918 6.5 Medium 2026-04-07
CVE-2026-39367 WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page CWE-79 5.4 Medium 2026-04-07
CVE-2026-39366 WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php CWE-345 6.5 Medium 2026-04-07
CVE-2026-35452 WWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php CWE-200 5.3 Medium 2026-04-06
CVE-2026-35450 WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php CWE-306 5.3 Medium 2026-04-06
CVE-2026-35449 WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php CWE-200 5.3 Medium 2026-04-06
CVE-2026-35448 WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php CWE-862 3.7 Low 2026-04-06
CVE-2026-35181 WWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php CWE-352 4.3 Medium 2026-04-06
CVE-2026-35180 WWBN AVideo affected by CSRF on Site Customization Endpoint Enables Logo Overwrite via Base64 File Write CWE-352 4.3 Medium 2026-04-06
CVE-2026-35179 WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php CWE-862 5.3 Medium 2026-04-06
CVE-2026-34740 AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation CWE-918 6.5 Medium 2026-03-31
CVE-2026-34739 AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php CWE-79 6.1 Medium 2026-03-31
CVE-2026-34738 AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter CWE-285 4.3 Medium 2026-03-31
CVE-2026-34737 AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug CWE-862 6.5 Medium 2026-03-31
CVE-2026-34733 AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard CWE-284 6.5 Medium 2026-03-31
CVE-2026-34732 AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints CWE-306 5.3 Medium 2026-03-31
CVE-2026-34731 AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php CWE-306 7.5 High 2026-03-31
CVE-2026-34716 AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification CWE-79 6.4 Medium 2026-03-31
CVE-2026-34613 AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins CWE-352 6.5 Medium 2026-03-31
CVE-2026-34611 AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users CWE-352 6.5 Medium 2026-03-31

All 220 known CVE vulnerabilities affecting AVideo with full Chinese analysis, references, and POCs where available.