Vulnerabilities in WWBN

323 results
Vexday analysis

O portfólio de vulnerabilidades do WWBN reúne 187 CVEs catalogadas, com 30 classificadas como críticas e 67 surgidas apenas nos últimos 90 dias — volume recente que indica aceleração no ritmo de descoberta e demanda atenção contínua ao ciclo de atualização. Embora nenhuma CVE esteja no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, o CVE-2022-30690 apresenta EPSS de 0,8358, sinalizando alta probabilidade estimada de exploração e devendo ser tratado com prioridade. A falha mais recorrente é CWE-79 (Cross-Site Scripting), categoria que, combinada com a existência de ao menos uma prova de conceito pública, amplia a superfície de risco para ambientes que ainda não aplicaram as correções disponíveis.

CVE-2022-32778HIGHAn information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cEPSS 2.4%CVE-2023-48728CRITICALA cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master comEPSS 2.3%CVE-2026-41304HIGHWWBN AVideo vulnerable to RCE caused by clonesite pluginEPSS 2.2%CVE-2026-29058CRITICALAVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.phpEPSS 2.1%CVE-2022-33149HIGHA sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted EPSS 1.9%CVE-2022-33147HIGHA sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted EPSS 1.9%CVE-2022-32282HIGHAn improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a useEPSS 1.8%CVE-2022-29468HIGHA cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP requesEPSS 1.7%CVE-2026-28501CRITICALWWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.phpEPSS 1.5%CVE-2023-49715MEDIUMA unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fEPSS 1.4%CVE-2023-49738HIGHAn information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A speciallyEPSS 1.3%CVE-2022-33148HIGHA sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted EPSS 1.2%CVE-2025-41420CRITICALA cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commEPSS 1.2%CVE-2025-48732HIGHAn incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request EPSS 1.1%CVE-2026-92580HIGHAVideo through 29.0 CloneSite Stored Shell Injection via SSH Password CSRFEPSS 1.1%CVE-2022-34652HIGHA sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted EPSS 1.1%CVE-2023-49862MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2023-49863MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%CVE-2023-47171MEDIUMAn information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev masterEPSS 1.1%CVE-2023-49864MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev masteEPSS 1.1%