VulnSea

wwbn has 95 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 84 in the last 90 days against 7 in the 90 before. The busiest recent month was September 2026 with 84. The median CVSS is 6.5 (medium), with 3 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-79 (18) and CWE-200 (13). Most affected products: AVideo (86), wwbn/avideo (9).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
84 prev 7

Products

  • AVideo 86
  • wwbn/avideo 9
95
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

wwbn vulnerabilities

CVEs affecting wwbn, newest first. Open any entry for full detail, references, and exploit status.

95 CVEsRSS

GHSA-rg7q-4223-phjwHigh· 7.5
3mo ago

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideovia GHSA
CVE-2026-34738Medium· 4.3
6mo ago

WWBN AVideo is an open source video platform

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "acti…

▾ Sunlitwwbn · avideoEPSS 0.27%via NVD
CVE-2026-56341High· 7.5
6mo ago

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records

▾ Twilightwwbn · wwbn/avideoEPSS 0.46%via GHSA
CVE-2026-56346Medium
6mo ago

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

AVideo has Unauthenticated PGP Message Decryption via Public Endpoint

▾ Sunlitwwbn · wwbn/avideoEPSS 0.61%via GHSA
CVE-2025-34438High· 8.1
9mo ago

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce own…

▾ Twilightwwbn · avideoEPSS 0.28%via NVD
wwbn vulnerabilities (CVEs) — page 4 · VulnSea