Wwbn/avideo
47 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Wwbn/avideo, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Wwbn/avideo CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 10 |
| 2026-04 | 20 |
| 2026-05 | 1 |
| 2026-06 | 2 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 47 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High7
- Medium4
Latest CVEs
The 15 most recently published vulnerabilities affecting Wwbn/avideo.
- GHSA-7cqp-7cfv-6c3qAVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel—
- GHSA-8whc-2wmv-ww35WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin—
- GHSA-qxvm-r42f-5p8jAVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin—
- GHSA-xr6f-h4x7-r6qpWWBN AVideo: RCE cause by clonesite plugin—
- GHSA-pq8p-wc4f-vg7jWWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection—
- GHSA-m7r8-6q9j-m2hcWWBN AVideo has an incomplete fix for CVE-2026-33500: XSS—
- GHSA-m63r-m9jh-3vc6WWBN AVideo has an Incomplete fix: Directory traversal bypass via query string in ReceiveImage downloadURL parameters—
- GHSA-8pv3-29pp-pf8fWWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver—
- GHSA-j432-4w3j-3w8jWWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL—
- GHSA-5879-4fmr-xwf2WWBN AVideo has an incomplete fix for CVE-2026-33293: Path Traversal—
- GHSA-ff5q-cc22-fgp4WWBN AVideo has a CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) Exposes Authenticated API Responses—
- GHSA-ccq9-r5cw-5hwqWWBN AVideo has CORS Origin Reflection with Credentials on Sensitive API Endpoints Enables Cross-Origin Account Takeover—
- GHSA-793q-xgj6-7frpWWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF—
- GHSA-hg7g-56h5-5pqrCAPTCHA Bypass in WWBN/AVideo via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure—
- GHSA-8qm8-g55h-xmqrWWBN AVideo is missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators—
Product grouping is registry-driven, with AI assist and human review. How it works