Loading...
Skip to main content
Packagist (PHP)

WWBN/AVideo Security Analysis

WWBN/AVideo has 28 known security vulnerabilities in Packagist (PHP). Upgrade to version 12.4 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

28 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 12.4

Upgrading to 12.4 or later resolves all 28 known vulnerabilities in WWBN/AVideo. Run: composer require WWBN/AVideo:^12.4

Is WWBN/AVideo in your project?

Check if you're affected and upgrade to 12.4 to stay secure.

28
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

28 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-40911
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
CRITICAL
10.4, 10.8, 11, 11.1 (+14 more)No fix available
CVE-2026-33478
AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection
CRITICAL
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33352
AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)
CRITICAL
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-29058
WWBN AVideo is vulnerable to unauthenticated OS Command Injection via base64Url in objects/getImage.php
CRITICAL
All versions7.0.0
CVE-2026-28502
AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction
CRITICAL
10.4, 10.8, 11, 11.1 (+9 more)No fix available
CVE-2026-28501
AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
CRITICAL
10.4, 10.8, 11, 11.1 (+9 more)No fix available
CVE-2026-54458
WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin
CRITICAL
All versionsNo fix available
CVE-2026-33716
AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php
CRITICAL
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33502
AVideo has Unauthenticated SSRF via plugin/Live/test.php
CRITICAL
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33351
AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass
CRITICAL
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2023-49599
WWBN AVideo Insufficient Entropy vulnerbaility
CRITICAL
10.4, 10.8, 11, 11.1 (+4 more)No fix available
CVE-2023-25313
AVideo contains Command injection when embedding a video link
CRITICAL
10.4, 10.8, 11, 11.1 (+3 more)12.4
CVE-2026-41304
WWBN AVideo: RCE cause by clonesite plugin
HIGH
10.4, 10.8, 11, 11.1 (+14 more)No fix available
CVE-2026-41064
WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection
HIGH
10.4, 10.8, 11, 11.1 (+14 more)No fix available
CVE-2026-45578
AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
HIGH
All versionsNo fix available
CVE-2026-33717
AVideo: Remote Code Execution via PHP Temp File in Encoder downloadURL
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33648
AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33647
AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33507
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33479
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-40909
WWBN AVideo has a Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)
HIGH
10.4, 10.8, 11, 11.1 (+14 more)No fix available
CVE-2026-33719
AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33513
AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33480
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
HIGH
10.4, 10.8, 11, 11.1 (+13 more)No fix available
CVE-2026-33039
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
HIGH
10.4, 10.8, 11, 11.1 (+12 more)No fix available
CVE-2026-49279
WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)
HIGH
10.4, 10.8, 11, 11.1 (+14 more)No fix available
CVE-2026-40925
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
HIGH
10.4, 10.8, 11, 11.1 (+14 more)No fix available
CVE-2026-60092
AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel
MEDIUM
10.4, 10.8, 11, 11.1 (+14 more)No fix available

About This Data

Vulnerability data for WWBN/AVideo is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related Packagist (PHP) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of WWBN/AVideo.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed