โ† All reports

The WWBN AVideo platform has critical security vulnerabilities in versions 29.0 and below that allow arbitrary file deletion and unauthorized access to API endpoints.

CybersecurityTechnologyConflictApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the WWBN AVideo open-source video platform, affecting versions 29.0 and below. These vulnerabilities involve path traversal and incomplete CORS origin validation, which could allow arbitrary file deletion and unauthorized access to API endpoints, respectively. These issues highlight security risks in open-source software and the importance of timely patches.

Claims

The WWBN AVideo platform has critical security vulnerabilities in versions 29.0 and below that allow arbitrary file deletion and unauthorized access to API endpoints.
Parent: CybersecurityEntity: WWBN AVideoImpact: negativeDate: Apr 22, 2026Target: The security of the WWBN AVideo platform

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24533 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24533 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24535 ๐Ÿ“Š Score: 8.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in the GET parameter... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24535 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability