Package impact

php Packagist / WWBN/AVideo

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-45619 medium 6.5 6.5 20d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS …
CVE-2026-45610 medium 6.5 6.5 20d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA val…
CVE-2026-47694 medium 5.4 5.4 6d ago WWBN AVideo: Stored XSS via unescaped Gallery category description
CVE-2026-45580 medium 5.4 5.4 20d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream …
CVE-2026-46337 medium 5.3 5.3 16d ago AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
CVE-2026-45620 medium 5.3 5.3 17d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) …
CVE-2026-45731 medium 4.9 4.9 17d ago WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line executi…
CVE-2026-47696 medium 4.3 4.3 6d ago WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint