Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

AVideo — Vulnerabilities & Security Advisories 220

All 220 CVE vulnerabilities found in AVideo, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities affecting AVideo, an open-source video sharing platform, categorized by common weakness enumeration types and associated tags. It aggregates a comprehensive collection of known flaws identified in the software, ranging from critical remote code execution risks to minor information disclosure issues. The dataset covers historical vulnerability data spanning from the initial releases of the software through the most recent updates, ensuring a chronological view of the product's security posture over time. Users can utilize this resource to track vendor advisories and security announcements related to AVideo, gaining insight into how the development team addresses reported issues and patches identified weaknesses. Additionally, the page allows for a deeper understanding of specific weakness classes by providing detailed descriptions and technical context for each vulnerability type, helping security professionals assess the nature and severity of potential threats. Visitors can also look up a product's vulnerability history to observe trends in vulnerability discovery and resolution, facilitating better risk management and informed decision-making regarding software adoption and maintenance. This information serves as a valuable reference for developers, system administrators, and security researchers seeking to understand the historical and current security landscape of the AVideo platform without relying on marketing language or specific CVE identifiers.

Vendor: WWBN

CVE ID Title CVSS Severity Published
CVE-2026-33237 AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation CWE-918 5.5 Medium 2026-03-20
CVE-2026-33043 AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS CWE-942 8.1 High 2026-03-20
CVE-2026-33041 AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php CWE-200 5.3 Medium 2026-03-20
CVE-2026-33039 AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy CWE-918 8.6 High 2026-03-20
CVE-2026-33038 AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments CWE-306 8.1 High 2026-03-20
CVE-2026-33037 WWBN AVideo has predictable default admin credentials in official Docker deployment path CWE-1188 8.1 High 2026-03-20
CVE-2026-33035 Unauthenticated Reflected XSS via innerHTML in AVideo CWE-79 6.1 - 2026-03-20
CVE-2026-30885 WWBN AVideo - Unauthenticated IDOR - Playlist Information Disclosure CWE-306 5.3AI Medium AI 2026-03-09
CVE-2026-28501 WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php CWE-89 9.8 Critical 2026-03-06
CVE-2026-28502 WWBN AVideo: Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction CWE-434 7.2 - 2026-03-06
CVE-2026-29093 WWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached port CWE-287 8.1 High 2026-03-06
CVE-2026-27732 AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php CWE-918 8.1 - 2026-02-24
CVE-2026-27568 AVideo has Stored Cross-Site Scripting via Markdown Comment Injection CWE-79 9.0 - 2026-02-24
CVE-2025-34433 AVideo < 20.1 Unauthenticated RCE via Predictable Installation Salt CWE-94 9.8AI Critical AI 2025-12-19
CVE-2025-34438 AVideo < 20.1 IDOR Arbitrary Video Rotation CWE-639 4.3AI Medium AI 2025-12-17
CVE-2025-34437 AVideo < 20.1 IDOR Arbitrary Comment Image Upload CWE-639 4.3AI Medium AI 2025-12-17
CVE-2025-34435 AVideo < 20.1 IDOR Arbitrary File Deletion CWE-639 6.5AI Medium AI 2025-12-17
CVE-2025-34436 AVideo < 20.1 IDOR Arbitrary File Upload CWE-639 6.5AI Medium AI 2025-12-17
CVE-2025-34434 AVideo < 20.1 ImageGallery Plugin Unauthenticated File Upload and Deletion CWE-306 9.1AI Critical AI 2025-12-17
CVE-2025-34439 AVideo < 20.1 Open Redirect via cancelUri Parameter CWE-601 6.1AI Medium AI 2025-12-17
CVE-2025-34440 AVideo < 20.1 Open Redirect via siteRedirectUri Parameter CWE-601 6.1AI Medium AI 2025-12-17
CVE-2025-34442 AVideo < 20.1 System Path Disclosure via Public API CWE-497 5.3AI Medium AI 2025-12-17
CVE-2025-34441 AVideo < 20.1 User Information Disclosure via Public API CWE-359 7.5AI High AI 2025-12-17
CVE-2025-46410 WWBN AVideo 跨站脚本漏洞 CWE-79 9.6 Critical 2025-07-24
CVE-2025-53084 多款产品跨站脚本漏洞 CWE-79 9.0 Critical 2025-07-24
CVE-2025-50128 WWBN AVideo 跨站脚本漏洞 CWE-79 9.6 Critical 2025-07-24
CVE-2025-36548 WWBN AVideo 跨站脚本漏洞 CWE-79 8.3 High 2025-07-24
CVE-2025-41420 WWBN AVideo 跨站脚本漏洞 CWE-79 9.6 Critical 2025-07-24
CVE-2025-25214 WWBN AVideo 竞争条件问题漏洞 CWE-362 8.8 High 2025-07-24
CVE-2025-48732 WWBN AVideo 安全漏洞 CWE-184 7.3 High 2025-07-24

All 220 known CVE vulnerabilities affecting AVideo with full Chinese analysis, references, and POCs where available.