VDB
Sign up

package

Packagist/WWBN/AVideo

pkg:packagist/WWBN/AVideo

MEDIUM5.7Packagist
GHSA-3mv2-vmwh-rwfx· CVE-2026-45610

AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA

Modified: 9/10/2026

CRITICAL9.6Packagist
GHSA-8whc-2wmv-ww35· CVE-2026-54458

WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin

Modified: 9/10/2026

MEDIUM6.5Packagist
GHSA-c3ch-22rq-xfwr· CVE-2026-45619

AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`

Modified: 9/10/2026

HIGH7.1Packagist
GHSA-cmcr-q4jf-p6q9· CVE-2026-39370

WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732)

Modified: 9/10/2026

HIGH7.6Packagist
GHSA-f4f9-627c-jh33· CVE-2026-39369

WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs

Modified: 9/10/2026

HIGH8.1Packagist
GHSA-qxvm-r42f-5p8j· CVE-2026-56345

AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin

Modified: 9/10/2026

MEDIUM5.3Packagist
GHSA-vpfx-pxqw-2w79· CVE-2026-45620

AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`

Modified: 9/10/2026