AVideo: Authenticated Arbitrary File Read in view/update.php
Modified: 9/10/2026
package
pkg:packagist/WWBN/AVideo
AVideo: Authenticated Arbitrary File Read in view/update.php
Modified: 9/10/2026
AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
Modified: 9/10/2026
WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
Modified: 9/10/2026
WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
Modified: 9/10/2026
WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint
Modified: 9/10/2026
AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`
Modified: 9/10/2026
WWBN AVideo: Stored XSS via unescaped Gallery category description
Modified: 9/10/2026
WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732)
Modified: 9/10/2026
WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
Modified: 9/10/2026
WWBN AVideo: Unauthenticated Reflected XSS via $_GET['search'] in AVideo YouTubeAPI Gallery Pagination
Modified: 9/10/2026
AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute
Modified: 9/10/2026
WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services
Modified: 9/10/2026
AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin
Modified: 9/10/2026
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`
Modified: 9/10/2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Modified: 9/10/2026
AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
Modified: 9/10/2026