VulnSea

WWBN has 93 CVEs on record. Disclosure cadence is accelerating: 83 in the last 90 days against 9 in the 90 before. The busiest recent month was September 2026 with 83. The median CVSS is 6.5 (medium), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (17) and CWE-200 (13). Most affected products: AVideo (84), wwbn/avideo (9).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
83 prev 9

Products

  • AVideo 84
  • wwbn/avideo 9
93
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

WWBN vulnerabilities

CVEs affecting WWBN, newest first. Open any entry for full detail, references, and exploit status.

93 CVEsRSS

CVE-2026-90546Medium· 4.3
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Att…

SunlitWWBN · AVideoEPSS 0.21%via NVD
CVE-2026-90543Medium· 5.3PoC
1w ago

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg…

TwilightWWBN · AVideoEPSS 0.35%via NVD
CVE-2026-90541Medium· 5.3
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET reque…

SunlitWWBN · AVideoEPSS 0.24%via NVD
CVE-2026-90540Medium· 4.3PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos …

TwilightWWBN · AVideoEPSS 0.16%via NVD
CVE-2026-89254High· 8.7
1w ago

AVideo CustomizeUser Stored XSS via field_name Parameter

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject …

TwilightWWBN · AVideoEPSS 0.28%via CVEORG
CVE-2026-89249High· 8.7
1w ago

AVideo YPTWallet Stored XSS via CryptoWallet Configuration

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in…

TwilightWWBN · AVideoEPSS 0.28%via CVEORG
CVE-2026-89244Medium· 6.1
1w ago

WWBN AVideo Reflected XSS via Gallery Category getBackURL

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href…

SunlitWWBN · AVideoEPSS 0.16%via CVEORG
CVE-2026-89239Medium· 6.1
1w ago

WWBN AVideo Reflected XSS via Referer Header Comment Breakout

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding…

SunlitWWBN · AVideoEPSS 0.16%via CVEORG
CVE-2026-89245Medium· 6.5PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can cra…

TwilightWWBN · AVideoEPSS 0.15%via NVD
CVE-2026-89243High· 8.1PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permi…

MidnightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-89251Medium· 6.5PoC
1w ago

AVideo Missing Authorization via AD_Server log.php Wallet Credit

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign vid…

TwilightWWBN · AVideoEPSS 0.15%via CVEORG
CVE-2026-89246Medium· 5.4PoC
1w ago

WWBN AVideo CSV Formula Injection via myComments.download.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated…

TwilightWWBN · AVideoEPSS 0.18%via CVEORG
CVE-2026-89241Medium· 6.1PoC
1w ago

WWBN AVideo Reflected XSS via confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can c…

TwilightWWBN · AVideoEPSS 0.20%via CVEORG
CVE-2026-89252Medium· 6.5PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's…

TwilightWWBN · AVideoEPSS 0.19%via NVD
CVE-2026-89256High· 8.7PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video…

MidnightWWBN · AVideoEPSS 0.32%via NVD
CVE-2026-89257Medium· 5.4PoC
1w ago

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the …

TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-89250High· 7.5PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can reque…

MidnightWWBN · AVideoEPSS 0.38%via NVD
CVE-2026-89240Medium· 6.1PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not…

TwilightWWBN · AVideoEPSS 0.24%via NVD
CVE-2026-89255High· 8.7PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated att…

MidnightWWBN · AVideoEPSS 0.35%via NVD
CVE-2026-89253High· 8.7PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() val…

MidnightWWBN · AVideoEPSS 0.35%via NVD
CVE-2026-89248Medium· 5.3PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebR…

TwilightWWBN · AVideoEPSS 0.38%via NVD
CVE-2026-89247Medium· 6.1PoC
1w ago

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script e…

TwilightWWBN · AVideoEPSS 0.22%via NVD
CVE-2026-89242High· 7.2PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated …

MidnightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-89148Medium· 5.4PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequ…

TwilightWWBN · AVideoEPSS 0.15%via NVD
CVE-2026-88872High· 7.1PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

MidnightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-88865High· 8.1
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exc…

TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-88871Medium· 4.3PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script …

TwilightWWBN · AVideoEPSS 0.14%via NVD
CVE-2026-88874High· 7.5PoC
1w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password…

MidnightWWBN · AVideoEPSS 0.51%via NVD
CVE-2026-88876High· 7.5PoC
1w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

MidnightWWBN · AVideoEPSS 0.32%via NVD
CVE-2026-88875Medium· 4.3
1w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and A…

SunlitWWBN · AVideoEPSS 0.22%via NVD
WWBN vulnerabilities (CVEs) — page 2 · VulnSea