Browse all 8 CVE security advisories affecting AVideo. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-60092 | AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel — AVideo CWE-79 | 6.1 | Medium | 2026-07-08 |
| CVE-2026-56346 | AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint — AVideo CWE-306 | 6.5 | Medium | 2026-06-20 |
| CVE-2026-56345 | AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint — AVideo CWE-287 | 8.1 | High | 2026-06-20 |
| CVE-2026-56341 | AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php — AVideo CWE-862 | 7.5 | High | 2026-06-20 |
| CVE-2026-56342 | AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter — AVideo CWE-918 | 6.8 | Medium | 2026-06-20 |
This page lists every published CVE security advisory associated with AVideo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.