PatchSiren

WWBN CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WWBN CVE published 2026-04-06

CVE-2026-35179

CVE-2026-35179 is a vulnerability in WWBN AVideo that allows unauthenticated users to make arbitrary Graph API calls through the server, potentially using stolen tokens or abusing the platform's own credentials. This issue exists in versions 26.0 and prior of the software. The SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Ins [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34739

AVideo User_Location plugin reflected XSS vulnerability CVE-2026-34739 allows attackers to inject arbitrary HTML and JavaScript via a crafted URL. This vulnerability affects AVideo versions 26.0 and prior. The User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other output encoding. Although the page is re [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34737

The CVE record for CVE-2026-34737 was published on 2026-03-31T21:16:32.247Z. WWBN AVideo versions 26.0 and prior contain a vulnerability in the StripeYPT plugin, which allows any logged-in user to cancel arbitrary Stripe subscriptions due to a bug in the retrieveSubscriptions() method. This issue has a CVSS score of 6.5 and a severity of MEDIUM. Users of WWBN AVideo who utilize Stripe subscriptions should [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34733

A vulnerability was found in the AVideo installation script, specifically in the deleteSystemdPrivate.php file. The script's CLI-only access guard contains a PHP operator precedence bug, allowing the script to be accessed via HTTP without authentication. This could lead to the deletion of files from the server's temp directory and disclosure of the temp directory contents in the response. The vulnerabilit [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34732

CVE-2026-34732 is a vulnerability in WWBN AVideo that exposes sensitive data via unauthenticated data listing endpoints. The AVideo CreatePlugin template for list.json.php does not include authentication or authorization checks, unlike companion templates add.json.php and delete.json.php. This omission affects 21 plugins, exposing user PII, payment transaction logs, IP addresses, user agents, and internal [truncated]

HIGH WWBN CVE published 2026-03-31

CVE-2026-34731

AVideo versions 26.0 and prior contain a vulnerability in the Live plugin's on_publish_done.php endpoint, allowing unauthenticated users to terminate any active live stream. This is possible because the endpoint processes RTMP callback events to mark streams as finished in the database without performing authentication or authorization checks. An attacker can exploit this by enumerating active stream keys [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34716

A medium-severity vulnerability was found in AVideo YPTSocket plugin versions 26.0 and prior. The plugin's caller feature renders incoming call notifications using jQuery Toast Plugin, passing the caller's display name directly as the heading parameter. An attacker can set their display name to an XSS payload and trigger code execution on any online user's browser simply by initiating a call. The vulnerab [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34613

The AVideo pluginSwitch.json.php endpoint allows administrators to enable or disable any installed plugin without validating a CSRF token. This, combined with SameSite=None on session cookies, could allow an attacker to disable critical security plugins by luring an admin to a malicious page. The vulnerability affects WWBN AVideo versions 26.0 and prior, and administrators and users should be aware of thi [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34611

A cross-site request forgery vulnerability exists in AVideo versions 26.0 and prior. The vulnerability is due to the lack of CSRF token validation in the objects/emailAllUsers.json.php endpoint, which allows administrators to send HTML emails to all registered users. An attacker can exploit this vulnerability by luring an administrator to a malicious page, allowing the attacker to send arbitrary HTML emai [truncated]

MEDIUM WWBN CVE published 2026-03-31

CVE-2026-34395

AVideo versions 26.0 and prior contain a vulnerability allowing any authenticated user to access all platform users' personal information and wallet balances. The vulnerability exists in the plugin/YPTWallet/view/users.json.php endpoint, which fails to properly validate user permissions. This issue can lead to unauthorized data exposure and potential exploitation by malicious actors.

HIGH WWBN CVE published 2026-03-31

CVE-2026-34394

AVideo, an open-source video platform, is vulnerable to a high-severity CSRF attack. The admin plugin configuration endpoint (admin/save.json.php) lacks CSRF token validation, allowing attackers to forge cross-origin POST requests and overwrite plugin settings on a victim administrator's session. This can lead to a complete takeover of platform functionality by reconfiguring payment processors, authentica [truncated]