WWBN has 95 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 84 in the last 90 days against 7 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.5 (medium), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (18) and CWE-200 (13). Most affected products: AVideo (86), wwbn/avideo (9).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 84 prev 7
Weakness classes
Products
- AVideo 86
- wwbn/avideo 9
Worst active — by depth score
CVE-2026-88869Critical· 9.3AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage63CVE-2026-86190Critical· 9.1WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash par…62CVE-2026-92580High· 8.8In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection61CVE-2026-89256High· 8.7AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML60CVE-2026-89255High· 8.7AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element60
WWBN vulnerabilities
CVEs affecting WWBN, newest first. Open any entry for full detail, references, and exploit status.
95 CVEsRSS
GHSA-rg7q-4223-phjwHigh· 7.5Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-34738Medium· 4.3WWBN AVideo is an open source video platform
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "acti…
CVE-2026-56341High· 7.5AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
CVE-2026-56346MediumAVideo has Unauthenticated PGP Message Decryption via Public Endpoint
AVideo has Unauthenticated PGP Message Decryption via Public Endpoint
CVE-2025-34438High· 8.1AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video
AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce own…