VulnSea

wwbn/avideo vulnerabilities

CVEs whose affected-version data names the wwbn/avideo package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-55173High· 8.1
3mo ago

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

▾ Twilightwwbn · wwbn/avideoEPSS 3.4%via GHSA
GHSA-7cqp-7cfv-6c3qMedium
3mo ago

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

▾ Sunlitwwbn · wwbn/avideovia GHSA
CVE-2026-33684Medium· 5.3
3mo ago

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

▾ Sunlitwwbn · wwbn/avideoEPSS 0.33%via GHSA
CVE-2026-33692High· 7.5
3mo ago

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

▾ Twilightwwbn · wwbn/avideoEPSS 0.45%via GHSA
CVE-2026-33731Medium· 6.5
3mo ago

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

▾ Sunlitwwbn · wwbn/avideoEPSS 0.21%via GHSA
GHSA-xj9w-cgqg-q897Medium· 6.5
3mo ago

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideovia GHSA
GHSA-rg7q-4223-phjwHigh· 7.5
3mo ago

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideovia GHSA
CVE-2026-56341High· 7.5
6mo ago

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideoEPSS 0.46%via GHSA
CVE-2026-56346Medium
6mo ago

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideoEPSS 0.61%via GHSA
wwbn/avideo vulnerabilities (CVEs) · VulnSea