Wwbn/avideo
This hub aggregates every CVE we track for Wwbn/avideo, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
47
CVEs tracked
5
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7CRITICAL5MEDIUM4
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2
10
20
1
2
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Wwbn/avideo.
- GHSA-7cqp-7cfv-6c3qAVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel
- GHSA-8whc-2wmv-ww35WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
- GHSA-qxvm-r42f-5p8jAVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin
- GHSA-xr6f-h4x7-r6qpWWBN AVideo: RCE cause by clonesite plugin
- GHSA-pq8p-wc4f-vg7jWWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection
- GHSA-m7r8-6q9j-m2hcWWBN AVideo has an incomplete fix for CVE-2026-33500: XSS
- GHSA-m63r-m9jh-3vc6WWBN AVideo has an Incomplete fix: Directory traversal bypass via query string in ReceiveImage downloadURL parameters
- GHSA-8pv3-29pp-pf8fWWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver
- GHSA-j432-4w3j-3w8jWWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
- GHSA-5879-4fmr-xwf2WWBN AVideo has an incomplete fix for CVE-2026-33293: Path Traversal
- GHSA-ff5q-cc22-fgp4WWBN AVideo has a CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) Exposes Authenticated API Responses
- GHSA-ccq9-r5cw-5hwqWWBN AVideo has CORS Origin Reflection with Credentials on Sensitive API Endpoints Enables Cross-Origin Account Takeover
- GHSA-793q-xgj6-7frpWWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF
- GHSA-hg7g-56h5-5pqrCAPTCHA Bypass in WWBN/AVideo via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure
- GHSA-8qm8-g55h-xmqrWWBN AVideo is missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators
Product normalization is registry-driven with AI assist and human review. How it works