Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AVideo — Vulnerabilities & Security Advisories 220

All 220 CVE vulnerabilities found in AVideo, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting AVideo, an open-source video sharing platform, categorized by common weakness enumeration types and associated tags. It aggregates a comprehensive collection of known flaws identified in the software, ranging from critical remote code execution risks to minor information disclosure issues. The dataset covers historical vulnerability data spanning from the initial releases of the software through the most recent updates, ensuring a chronological view of the product's security posture over time. Users can utilize this resource to track vendor advisories and security announcements related to AVideo, gaining insight into how the development team addresses reported issues and patches identified weaknesses. Additionally, the page allows for a deeper understanding of specific weakness classes by providing detailed descriptions and technical context for each vulnerability type, helping security professionals assess the nature and severity of potential threats. Visitors can also look up a product's vulnerability history to observe trends in vulnerability discovery and resolution, facilitating better risk management and informed decision-making regarding software adoption and maintenance. This information serves as a valuable reference for developers, system administrators, and security researchers seeking to understand the historical and current security landscape of the AVideo platform without relying on marketing language or specific CVE identifiers.

Vendor: WWBN

CVE ID Title CVSS Severity Published
CVE-2026-34396 AVideo: Stored XSS via Unescaped Plugin Configuration Values in Admin Panel CWE-79 6.1 Medium 2026-03-31
CVE-2026-34394 AVideo: CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking CWE-352 8.1 High 2026-03-31
CVE-2026-34395 AVideo: Mass User PII Disclosure via Missing Authorization in YPTWallet users.json.php CWE-862 6.5 Medium 2026-03-31
CVE-2026-34375 AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page CWE-79 8.2 High 2026-03-27
CVE-2026-34374 AVideo has SQL Injection in Live_schedule::keyExists() via Unparameterized Stream Key CWE-89 9.1 Critical 2026-03-27
CVE-2026-34369 AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sources Without Password Verification CWE-862 5.3 Medium 2026-03-27
CVE-2026-34368 AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance CWE-362 5.3 Medium 2026-03-27
CVE-2026-34364 AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.php CWE-863 5.3 Medium 2026-03-27
CVE-2026-34362 AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket() CWE-613 5.4 Medium 2026-03-27
CVE-2026-34247 AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream Posters and Trigger False Socket Notifications CWE-862 5.4 Medium 2026-03-27
CVE-2026-34245 AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking CWE-862 6.3 Medium 2026-03-27
CVE-2026-33867 AVideo has Plaintext Video Password Storage CWE-312 8.1 - 2026-03-27
CVE-2026-33770 AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables CWE-89 9.8 - 2026-03-27
CVE-2026-33767 AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query CWE-89 9.8 - 2026-03-27
CVE-2026-33766 AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints CWE-918 8.2 - 2026-03-27
CVE-2026-33764 AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcriptions CWE-639 4.3 Medium 2026-03-27
CVE-2026-33763 AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean Oracle CWE-307 5.3 Medium 2026-03-27
CVE-2026-33761 AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings CWE-862 5.3 Medium 2026-03-27
CVE-2026-33759 AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents CWE-862 5.3 Medium 2026-03-27
CVE-2026-33723 AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php CWE-89 7.1 High 2026-03-23
CVE-2026-33719 AVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment in status.json.php CWE-306 8.6 High 2026-03-23
CVE-2026-33717 AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort CWE-434 8.8 High 2026-03-23
CVE-2026-33716 AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php CWE-287 9.4 Critical 2026-03-23
CVE-2026-33690 AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr() CWE-348 5.3 Medium 2026-03-23
CVE-2026-33688 AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint CWE-204 5.3 Medium 2026-03-23
CVE-2026-33685 AVideo Allows Unauthenticated Access to AD_Server reports.json.php that Exposes Ad Campaign Analytics and User Data CWE-862 5.3 Medium 2026-03-23
CVE-2026-33683 AVideo vulnerable to Stored XSS via html_entity_decode() Reversing xss_esc() Sanitization in Channel About Field CWE-79 5.4 Medium 2026-03-23
CVE-2026-33681 AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name CWE-22 7.2 High 2026-03-23
CVE-2026-33651 AVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_id in Scheduler_commands::getAllActiveOrToRepeat() CWE-89 8.1 High 2026-03-23
CVE-2026-33650 AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion CWE-863 7.6 High 2026-03-23

All 220 known CVE vulnerabilities affecting AVideo with full Chinese analysis, references, and POCs where available.