CVE Tools

Wwbn/avideo

47 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Wwbn/avideo, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Wwbn/avideo CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Wwbn/avideo CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-022
2026-0310
2026-0420
2026-051
2026-062
2026-070
2026-080
2026-090

Severity

How the 47 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical531%
  • High744%
  • Medium425%

Latest CVEs

The 15 most recently published vulnerabilities affecting Wwbn/avideo.

  1. GHSA-7cqp-7cfv-6c3qAVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel—
  2. GHSA-8whc-2wmv-ww35WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin—
  3. GHSA-qxvm-r42f-5p8jAVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin—
  4. GHSA-xr6f-h4x7-r6qpWWBN AVideo: RCE cause by clonesite plugin—
  5. GHSA-pq8p-wc4f-vg7jWWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection—
  6. GHSA-m7r8-6q9j-m2hcWWBN AVideo has an incomplete fix for CVE-2026-33500: XSS—
  7. GHSA-m63r-m9jh-3vc6WWBN AVideo has an Incomplete fix: Directory traversal bypass via query string in ReceiveImage downloadURL parameters—
  8. GHSA-8pv3-29pp-pf8fWWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver—
  9. GHSA-j432-4w3j-3w8jWWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL—
  10. GHSA-5879-4fmr-xwf2WWBN AVideo has an incomplete fix for CVE-2026-33293: Path Traversal—
  11. GHSA-ff5q-cc22-fgp4WWBN AVideo has a CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) Exposes Authenticated API Responses—
  12. GHSA-ccq9-r5cw-5hwqWWBN AVideo has CORS Origin Reflection with Credentials on Sensitive API Endpoints Enables Cross-Origin Account Takeover—
  13. GHSA-793q-xgj6-7frpWWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF—
  14. GHSA-hg7g-56h5-5pqrCAPTCHA Bypass in WWBN/AVideo via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure—
  15. GHSA-8qm8-g55h-xmqrWWBN AVideo is missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store