Daniel Neto
98 exploits
Active since Dec 2025
WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
CVSS 7.6
WWBN AVideo has IDOR in Live Restreams list.json.php that Exposes Other Users' Stream Keys and OAuth Tokens
CVSS 6.5
WWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)
CVSS 8.7
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
CVSS 10.0
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
CVSS 8.3
WWBN AVideo Vulnerable to CSRF in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
CVSS 7.1
AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion
CVSS 5.4
WWBN AVideo's missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators
CVSS 5.4
WWBN/AVideo has CAPTCHA Bypass via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
CVSS 5.3
AVideo has an incomplete fix for CVE-2026-33039 (SSRF)
CVSS 8.6
AVideos has CORS Origin Reflection with Credentials on Sensitive API Endpoints that Enables Cross-Origin Account Takeover
CVSS 8.1
AVideo has CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) that Exposes Authenticated API Responses
CVSS 7.1
AVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideo
CVSS 8.1
AVideo's SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
CVSS 7.7
WWBN AVideo Vulnerable to stored XSS via Unanchored Duration Regex in Video Encoder Receiver
CVSS 5.4
WWBN/AVideo has an incomplete fix for a directory traversal bypass via query string in ReceiveImage downloadURL parameters
CVSS 6.5
WWBN AVideo has incomplete fix for CVE-2026-33500 (XSS)
CVSS 5.4
AVideo has an incomplete fix for CVE-2026-33502 (Command Injection)
CVSS 9.3
WWBN AVideo vulnerable to RCE caused by clonesite plugin
WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php
CVSS 6.5
WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page
CVSS 5.4
AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents
CVSS 5.3
AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings
CVSS 5.3
AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean Oracle
CVSS 5.3
AVideo: IDOR in AI Plugin Allows Stealing Other Users' AI-Generated Metadata and Transcriptions
CVSS 4.3