19 Total CVEs
19 AI Analyzed
0 CISA KEV
7 Critical

Profile

0% ended up actively exploited 0 of 19 added to CISA KEV
37% rated critical (CVSS 9.0+) 7 critical, 12 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

18 CVEs in the last 12 months

Products

  • AVideo18

1 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-19 of 19 CVEs
CVE-2026-85160
Analyzed
8.1
WWBN AVideo

AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete...

2026-09-04
CVE-2026-85154
Analyzed
9.8
WWBN AVideo

WWBN AVideo contains an authentication failure where the video_id_hash credential functions as a permanent, non-revocable bearer token, allowing unaut...

2026-09-04
CVE-2026-84482
Analyzed
8.8
WWBN AVideo

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to...

2026-09-02
CVE-2026-84480
Analyzed
9.8
WWBN AVideo

WWBN AVideo fails to validate password recovery token expiration, allowing unauthenticated attackers to reuse expired tokens to reset user passwords a...

2026-09-02
CVE-2026-84479
Analyzed
9.1
WWBN AVideo

WWBN AVideo improperly relies on the User-Agent header for authentication security, allowing attackers to bypass two-factor authentication and securit...

2026-09-02
CVE-2026-82648
Analyzed
7.1
WWBN AVideo

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses w...

2026-09-04
CVE-2026-82645
Analyzed
8.6
WWBN AVideo

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Sup...

2026-08-31
CVE-2026-82644
Analyzed
7.5
WWBN AVideo

WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 ot...

2026-08-31
CVE-2026-64625
Analyzed
9.8
WWBN AVideo

AVideo contains an OS command injection vulnerability in the Live plugin, where insufficient escaping allows attackers to execute arbitrary system com...

2026-07-21
CVE-2026-63305
Analyzed
8.1
WWBN AVideo

AVideo through 29

2026-07-17
CVE-2026-63304
Analyzed
8.1
WWBN AVideo

AVideo through 29

2026-07-17
CVE-2026-59808
Analyzed
8.8
WWBN AVideo

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials f...

2026-08-23
CVE-2026-59256
Analyzed
7.5
WWBN AVideo

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or...

2026-08-23
CVE-2026-58003
Analyzed
7.1
WWBN AVideo

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow

2026-08-23
CVE-2026-55173
Analyzed
8.1
WWBN AVideo

WWBN AVideo is an open source video platform

2026-07-17
CVE-2026-54458
Analyzed
9.6
WWBN AVideo

A stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin of AVideo allows unauthenticated attackers to hijack administrative sessions v...

2026-07-16
CVE-2026-40911
Analyzed
10
WWBN AVideo

A WebSocket-based cross-site scripting (XSS) vulnerability in the AVideo YPTSocket plugin allows unauthenticated attackers to achieve universal accoun...

2026-04-22
CVE-2026-34374
Analyzed
9.1
WWBN AVideo

WWBN AVideo contains a critical SQL injection vulnerability in its stream key lookup path, allowing unauthenticated attackers to execute malicious dat...

2026-03-28
CVE-2025-36548
Analyzed
8.3
WWBN Multiple Products

A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14

2025-07-25