wwbn
197 tracked vulnerabilities.
CVE-2026-29093
HIGH
WWBN AVideo <24.0 - Session Hijacking
Mar 06, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-28502
HIGH
WWBN AVideo <24.0 - Authenticated RCE
Mar 06, 2026
CVSS 8.8
EPSS 0.00
CVE-2026-28501
CRITICAL
WWBN AVideo < 24.0 - Unauthenticated SQL Injection via catName Parameter in JSON POST Request
Mar 06, 2026
CVSS 9.8
EPSS 0.27
CVE-2026-27732
HIGH
WWBN AVideo < 22.0 - Authenticated Server-Side Request Forgery via aVideoEncoder.json.php DownloadURL Parameter
Feb 24, 2026
CVSS 8.1
EPSS 0.00
CVE-2026-27568
MEDIUM
WWBN AVideo < 21.0 - Authenticated Stored Cross-Site Scripting via Markdown Link Injection
Feb 24, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-34442
HIGH
AVideo < 20.1 - Sensitive System Information Exposure via Public API Endpoints
Dec 17, 2025
CVSS 7.5
EPSS 0.41
CVE-2025-34441
HIGH
AVideo < 20.1 - Unauthenticated Exposure of Sensitive User Information via Public API
Dec 17, 2025
CVSS 7.5
EPSS 0.41
CVE-2025-34440
MEDIUM
AVideo < 20.1 - Open Redirect via siteRedirectUri Parameter
Dec 17, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-34439
MEDIUM
AVideo < 20.1 - Open Redirect via cancelUri Parameter
Dec 17, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-34438
HIGH
AVideo < 20.1 - Insecure Direct Object Reference in Video Rotation Metadata
Dec 17, 2025
CVSS 8.1
EPSS 0.00
CVE-2025-34437
HIGH
AVideo < 20.1 - Authenticated Arbitrary Comment Image Upload via Missing Ownership Check
Dec 17, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-34436
HIGH
AVideo < 20.1 - Authenticated Arbitrary File Upload via Insecure Direct Object Reference
Dec 17, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-34435
MEDIUM
AVideo < 20.1 - Authenticated Arbitrary File Deletion via IDOR
Dec 17, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-34434
CRITICAL
AVideo < 20.1 - Unauthenticated Arbitrary File Upload and Deletion via ImageGallery Plugin
Dec 17, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-53084
CRITICAL
WWBN AVideo 14.4 and dev master - Cross-Site Scripting via VideosList Page Parameter
Jul 24, 2025
CVSS 9.0
EPSS 0.00
CVE-2025-50128
CRITICAL
WWBN AVideo 14.4 and dev master - Stored Cross-Site Scripting via videoNotFound 404ErrorMsg Parameter
Jul 24, 2025
CVSS 9.6
EPSS 0.00
CVE-2025-48732
HIGH
WWBN AVideo 14.4 and dev master - Remote Code Execution via .phar File Request
Jul 24, 2025
CVSS 7.3
EPSS 0.03
CVE-2025-46410
CRITICAL
WWBN AVideo 14.4 and dev master - Cross-Site Scripting via managerPlaylists PlaylistOwnerUsersId Parameter
Jul 24, 2025
CVSS 9.6
EPSS 0.00
CVE-2025-41420
CRITICAL
WWBN AVideo 14.4 and dev master - Cross-Site Scripting via UserLogin cancelUri Parameter
Jul 24, 2025
CVSS 9.6
EPSS 0.01
CVE-2025-36548
HIGH
WWBN AVideo 14.4 and dev master - Cross-Site Scripting via LoginWordPress cancelUri Parameter
Jul 24, 2025
CVSS 8.3
EPSS 0.01
CVE-2025-25214
HIGH
WWBN AVideo 14.4 RCE via Race Condition in aVideoEncoder.json.php Unzip
Jul 24, 2025
CVSS 8.8
EPSS 0.01
CVE-2024-34899
MEDIUM
WWBN AVideo 12.4 - Cross-Site Scripting
May 14, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-31819
CRITICAL
WWBN AVideo 12.4-14.2 - Remote Code Execution via systemRootPath Parameter
Apr 10, 2024
CVSS 9.8
EPSS 0.86
CVE-2023-50172
MEDIUM
WWBN AVideo - Recovery Notification Bypass via Captcha Validation
Jan 10, 2024
CVSS 5.3
EPSS 0.00
CVE-2023-49864
MEDIUM
WWBN AVideo - Arbitrary File Read via aVideoEncoderReceiveImage.json.php downloadURL_image Parameter
Jan 10, 2024
CVSS 6.5
EPSS 0.00
Quick Filters