The WWBN AVideo platform has multiple security vulnerabilities that expose it to potential exploitation by malicious actors.
Claims
The WWBN AVideo platform has multiple security vulnerabilities that expose it to potential exploitation by malicious actors.
Parent: CybersecurityEntity: WWBN AVideoImpact: negativeDate: Apr 21, 2026Target: The security of the WWBN AVideo platform
Source posts
๐จ EUVD-2026-24284
๐ Score: 6.5/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and prior, the endpoint `plugin/Live/view/Live_restreams/list.json.php` contains an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user with streaming permission ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24284
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24286
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and prior, the file `git.json.php` at the web root executes `git log -1` and returns the full output as JSON to any unauthenticated user. This exposes the exact deployed commit hash (enabling version...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24286
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24288
๐ Score: 8.7/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenating `$_POST['flag']` into the path at line 30 without any sanitization. The `$_POST['code']` param...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24288
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24485
๐ Score: 8.3/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST` but protects the endpoint only with `User::isAdmin()`. It doe...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24485
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability