Avideo
This hub aggregates every CVE we track for Avideo, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
218
CVEs tracked
28
Critical
84
High
0
In CISA KEV
Severity distribution
MEDIUM105HIGH84CRITICAL28LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
7
0
0
0
0
9
0
5
80
31
21
5
12
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Avideo.
- CVE-2026-64626AVideo Encoder downloadURL SSRF via unpinned retry fallback6.4
- CVE-2026-64625AVideo before 29.0 OS Command Injection via execAsync9.8
- CVE-2026-33731AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data6.5
- CVE-2026-55173AVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink8.1
- CVE-2026-33692AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration7.5
- CVE-2026-63305AVideo through 29.0 OS Command Injection via ffmpeg.json.php8.1
- CVE-2026-63304AVideo through 29.0 OS Command Injection via listFFmpegProcesses8.1
- CVE-2026-54458AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin9.6
- CVE-2026-50183WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section4.7
- CVE-2026-50182AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Gallery Pagination6.1
- CVE-2026-33684AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions5.3
- CVE-2026-60092AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel6.1
- CVE-2026-56347AVideo TopMenu Plugin - Stored Cross-Site Scripting via Unescaped Menu Item Fields6.1
- CVE-2026-56345AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint8.1
- CVE-2026-56346AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint6.5
Product normalization is registry-driven with AI assist and human review. How it works