WWBN/AVideo Security Analysis
WWBN/AVideo has 28 known security vulnerabilities in Packagist (PHP). Upgrade to version 12.4 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Low Immediate Risk
No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.
Recommended safe version: 12.4
Upgrading to 12.4 or later resolves all 28 known vulnerabilities in WWBN/AVideo. Run: composer require WWBN/AVideo:^12.4
Is WWBN/AVideo in your project?
Check if you're affected and upgrade to 12.4 to stay secure.
Vulnerabilities
28 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2026-40911 WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks | CRITICAL | 10.4, 10.8, 11, 11.1 (+14 more) | No fix available |
| CVE-2026-33478 AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection | CRITICAL | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33352 AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass) | CRITICAL | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-29058 WWBN AVideo is vulnerable to unauthenticated OS Command Injection via base64Url in objects/getImage.php | CRITICAL | All versions | 7.0.0 |
| CVE-2026-28502 AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction | CRITICAL | 10.4, 10.8, 11, 11.1 (+9 more) | No fix available |
| CVE-2026-28501 AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php | CRITICAL | 10.4, 10.8, 11, 11.1 (+9 more) | No fix available |
| CVE-2026-54458 WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin | CRITICAL | All versions | No fix available |
| CVE-2026-33716 AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php | CRITICAL | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33502 AVideo has Unauthenticated SSRF via plugin/Live/test.php | CRITICAL | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33351 AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass | CRITICAL | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2023-49599 WWBN AVideo Insufficient Entropy vulnerbaility | CRITICAL | 10.4, 10.8, 11, 11.1 (+4 more) | No fix available |
| CVE-2023-25313 AVideo contains Command injection when embedding a video link | CRITICAL | 10.4, 10.8, 11, 11.1 (+3 more) | 12.4 |
| CVE-2026-41304 WWBN AVideo: RCE cause by clonesite plugin | HIGH | 10.4, 10.8, 11, 11.1 (+14 more) | No fix available |
| CVE-2026-41064 WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection | HIGH | 10.4, 10.8, 11, 11.1 (+14 more) | No fix available |
| CVE-2026-45578 AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL | HIGH | All versions | No fix available |
| CVE-2026-33717 AVideo: Remote Code Execution via PHP Temp File in Encoder downloadURL | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33648 AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33647 AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33507 AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33479 AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-40909 WWBN AVideo has a Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE) | HIGH | 10.4, 10.8, 11, 11.1 (+14 more) | No fix available |
| CVE-2026-33719 AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33513 AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP) | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33480 AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy | HIGH | 10.4, 10.8, 11, 11.1 (+13 more) | No fix available |
| CVE-2026-33039 AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy | HIGH | 10.4, 10.8, 11, 11.1 (+12 more) | No fix available |
| CVE-2026-49279 WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass) | HIGH | 10.4, 10.8, 11, 11.1 (+14 more) | No fix available |
| CVE-2026-40925 WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials | HIGH | 10.4, 10.8, 11, 11.1 (+14 more) | No fix available |
| CVE-2026-60092 AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel | MEDIUM | 10.4, 10.8, 11, 11.1 (+14 more) | No fix available |
About This Data
Vulnerability data for WWBN/AVideo is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Packagist (PHP) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of WWBN/AVideo.