Daniel Neto
98 exploits
Active since Dec 2025
AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints
CVSS 6.5
AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query
CVSS 8.8
AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables
CVSS 9.8
AVideo has Plaintext Video Password Storage
CVSS 7.5
AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking
CVSS 6.3
AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream Posters and Trigger False Socket Notifications
CVSS 5.4
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()
CVSS 5.4
AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.php
CVSS 5.3
AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance
CVSS 5.3
AVIdeo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sources Without Password Verification
CVSS 5.3
AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page
CVSS 8.2
AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload
CVSS 8.8
AVideo's Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion
CVSS 7.6
AVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_id in Scheduler_commands::getAllActiveOrToRepeat()
CVSS 8.1
AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name
CVSS 7.2
AVideo Allows Unauthenticated Access to AD_Server reports.json.php that Exposes Ad Campaign Analytics and User Data
CVSS 5.3
AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint
CVSS 5.3
AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
CVSS 9.4
AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with Resolution Validation Abort
CVSS 8.8
AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subscribe.php
CVSS 7.1
WWBN AVideo <=26.0 - Info Disclosure
CVSS 7.5
WWBN AVideo <=26.0 - Command Injection
CVSS 8.8
WWBN AVideo <=26.0 - XSS
CVSS 5.4
WWBN AVideo <=26.0 - IP Spoofing
CVSS 5.3
WWBN AVideo <=26.0 - Auth Bypass
CVSS 8.6