VulnSea

WWBN has 93 CVEs on record. Disclosure cadence is accelerating: 83 in the last 90 days against 9 in the 90 before. The busiest recent month was September 2026 with 83. The median CVSS is 6.5 (medium), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (17) and CWE-200 (13). Most affected products: AVideo (84), wwbn/avideo (9).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
83 prev 9

Products

  • AVideo 84
  • wwbn/avideo 9
93
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

WWBN vulnerabilities

CVEs affecting WWBN, newest first. Open any entry for full detail, references, and exploit status.

93 CVEsRSS

CVE-2026-88873High· 7.1
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests …

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests …

TwilightWWBN · AVideoEPSS 0.14%via NVD
CVE-2026-88870High· 7.1
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages wit…

TwilightWWBN · AVideoEPSS 0.13%via NVD
CVE-2026-88869Critical· 9.3PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated at…

AbyssalWWBN · AVideoEPSS 0.48%via NVD
CVE-2026-88868High· 8.7
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permiss…

TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-88867High· 8.7PoC
1w ago

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Cate…

MidnightWWBN · AVideoEPSS 0.32%via NVD
CVE-2026-88866High· 8.7PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers …

MidnightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-86718High· 7.1PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by maki…

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by maki…

MidnightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-86729High· 7.4
1w ago

WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path

WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes …

TwilightWWBN · AVideoEPSS 0.22%via NVD
CVE-2026-86728High· 7.5
1w ago

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users

AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential use…

TwilightWWBN · AVideoEPSS 0.32%via NVD
CVE-2026-86727High· 7.5PoC
1w ago

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication

AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers ca…

MidnightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-86726Medium· 6.5
1w ago

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams

AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fa…

SunlitWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-86725High· 7.1PoC
1w ago

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records.…

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records.…

MidnightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-86724Medium· 6.5
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session…

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session…

SunlitWWBN · AVideoEPSS 0.13%via NVD
CVE-2026-86723High· 8.1
1w ago

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. A…

TwilightWWBN · AVideoEPSS 0.27%via NVD
CVE-2026-86722High· 8.1PoC
1w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-fa…

MidnightWWBN · AVideoEPSS 0.27%via NVD
CVE-2026-86721High· 7.5
1w ago

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints

AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish t…

TwilightWWBN · AVideoEPSS 0.29%via NVD
CVE-2026-86720High· 8.1PoC
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. …

MidnightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-86719Medium· 5.4
1w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id fro…

SunlitWWBN · AVideoEPSS 0.11%via NVD
CVE-2026-86190Critical· 9.1PoC
2w ago

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…

AbyssalWWBN · AVideoEPSS 0.27%via NVD
CVE-2026-86189Critical· 9.8
2w ago

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers ca…

MidnightWWBN · AVideoEPSS 0.41%via NVD
CVE-2026-86188High· 7.2PoC
2w ago

AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism

AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send craft…

MidnightWWBN · AVideoEPSS 0.25%via NVD
CVE-2026-86187Medium· 5.9
2w ago

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers

WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through of…

SunlitWWBN · AVideoEPSS 0.22%via NVD
CVE-2026-86186Medium· 6.5PoC
2w ago

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to d…

TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-55173High· 8.1
3mo ago

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink

Twilightwwbn · wwbn/avideoEPSS 3.4%via GHSA
GHSA-7cqp-7cfv-6c3qMedium
3mo ago

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel

Sunlitwwbn · wwbn/avideovia GHSA
CVE-2026-33684Medium· 5.3
3mo ago

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

AVideo's Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions

Sunlitwwbn · wwbn/avideoEPSS 0.33%via GHSA
CVE-2026-33692High· 7.5
3mo ago

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration

Twilightwwbn · wwbn/avideoEPSS 0.45%via GHSA
CVE-2026-33731Medium· 6.5
3mo ago

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data

Sunlitwwbn · wwbn/avideoEPSS 0.21%via GHSA
GHSA-xj9w-cgqg-q897Medium· 6.5
3mo ago

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

Sunlitwwbn · wwbn/avideovia GHSA
GHSA-rg7q-4223-phjwHigh· 7.5
3mo ago

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Twilightwwbn · wwbn/avideovia GHSA
WWBN vulnerabilities (CVEs) — page 3 · VulnSea