Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

AVideo — Vulnerabilities & Security Advisories 193

All 193 CVE vulnerabilities found in AVideo, with AI-generated Chinese analysis, references, and POCs.

This page is a comprehensive vulnerability aggregation resource for AVideo, focusing on common weakness enumeration tags associated with the platform. It collects and organizes detailed reports on security flaws, including cross-site scripting, SQL injection, path traversal, and authentication bypass issues discovered within the AVideo software ecosystem. The data spans from the initial public disclosure of early vulnerabilities through to the most recent patches released by the vendor, ensuring a complete historical record of security incidents. By navigating this collection, security professionals and administrators can efficiently track the vendor’s advisory timeline to understand the pace and nature of remediation efforts. Users can also delve into the specifics of particular weakness classes to analyze attack vectors and mitigation strategies relevant to AVideo deployments. Additionally, the page serves as a lookup tool for reviewing a specific product version’s vulnerability history, helping teams assess risk exposure and prioritize updates based on past incident patterns. This centralized view facilitates informed decision-making for system hardening and compliance audits without requiring searches across multiple disparate sources. The information is presented to support proactive security management, allowing teams to anticipate potential threats and apply appropriate controls effectively. All entries are curated to provide accurate technical context, enabling deeper analysis of how specific defects impact the overall security posture of the application. This resource aims to reduce the time spent on information gathering, thereby accelerating the response to emerging security challenges in environments utilizing AVideo.

Vendor: WWBN

CVE IDTitleCVSSSeverityPublished
CVE-2026-41056 AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover CWE-942 8.1 High2026-04-21
CVE-2026-41055 AVideo has an incomplete fix for CVE-2026-33039 (SSRF) CWE-918 8.6 High2026-04-21
CVE-2026-40935 WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure CWE-804 5.3 Medium2026-04-21
CVE-2026-40929 WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators CWE-352 5.4 Medium2026-04-21
CVE-2026-40928 AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion CWE-352 5.4 Medium2026-04-21
CVE-2026-40926 WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script) CWE-352 7.1 High2026-04-21
CVE-2026-40925 WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials CWE-352 8.3 High2026-04-21
CVE-2026-40911 WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks CWE-94 10.0 Critical2026-04-21
CVE-2026-40909 WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE) CWE-22 8.7 High2026-04-21
CVE-2026-40908 WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php that Exposes Developer Emails and Deployed Version CWE-200 5.3 Medium2026-04-21
CVE-2026-40907 WWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens CWE-639 6.5 Medium2026-04-21
CVE-2026-39370 WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732) CWE-918 7.1 High2026-04-07
CVE-2026-39369 WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs CWE-22 7.6 High2026-04-07
CVE-2026-39368 WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services CWE-918 6.5 Medium2026-04-07
CVE-2026-39367 WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page CWE-79 5.4 Medium2026-04-07
CVE-2026-39366 WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php CWE-345 6.5 Medium2026-04-07
CVE-2026-35452 WWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php CWE-200 5.3 Medium2026-04-06
CVE-2026-35450 WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php CWE-306 5.3 Medium2026-04-06
CVE-2026-35449 WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php CWE-200 5.3 Medium2026-04-06
CVE-2026-35448 WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php CWE-862 3.7 Low2026-04-06
CVE-2026-35181 WWBN AVideo Affected by CSRF on Player Skin Configuration via admin/playerUpdate.json.php CWE-352 4.3 Medium2026-04-06
CVE-2026-35180 WWBN AVideo affected by CSRF on Site Customization Endpoint Enables Logo Overwrite via Base64 File Write CWE-352 4.3 Medium2026-04-06
CVE-2026-35179 WWBN AVideo Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php CWE-862 5.3 Medium2026-04-06
CVE-2026-34740 AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation CWE-918 6.5 Medium2026-03-31
CVE-2026-34739 AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php CWE-79 6.1 Medium2026-03-31
CVE-2026-34738 AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter CWE-285 4.3 Medium2026-03-31
CVE-2026-34737 AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug CWE-862 6.5 Medium2026-03-31
CVE-2026-34733 AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard CWE-284 6.5 Medium2026-03-31
CVE-2026-34732 AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints CWE-306 5.3 Medium2026-03-31
CVE-2026-34731 AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php CWE-306 7.5 High2026-03-31

All 193 known CVE vulnerabilities affecting AVideo with full Chinese analysis, references, and POCs where available.