Vulnerabilities in WWBN

323 results
Vexday analysis

O portfólio de vulnerabilidades do WWBN reúne 187 CVEs catalogadas, com 30 classificadas como críticas e 67 surgidas apenas nos últimos 90 dias — volume recente que indica aceleração no ritmo de descoberta e demanda atenção contínua ao ciclo de atualização. Embora nenhuma CVE esteja no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, o CVE-2022-30690 apresenta EPSS de 0,8358, sinalizando alta probabilidade estimada de exploração e devendo ser tratado com prioridade. A falha mais recorrente é CWE-79 (Cross-Site Scripting), categoria que, combinada com a existência de ao menos uma prova de conceito pública, amplia a superfície de risco para ambientes que ainda não aplicaram as correções disponíveis.

CVE-2023-47862CRITICALA local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A speciEPSS 1.1%CVE-2025-25214HIGHA race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. EPSS 1.0%CVE-2025-36548HIGHA cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and EPSS 1.0%CVE-2023-49599CRITICALAn insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially cEPSS 1.0%CVE-2023-49589HIGHAn insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commiEPSS 0.9%CVE-2022-32768MEDIUMMultiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7cEPSS 0.9%CVE-2026-72748MEDIUMAVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.phpEPSS 0.9%CVE-2023-50172MEDIUMA recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master coEPSS 0.8%CVE-2023-47861CRITICALA cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 1EPSS 0.8%CVE-2022-32769MEDIUMMultiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7cEPSS 0.8%CVE-2025-50128CRITICALA cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev masteEPSS 0.8%CVE-2025-46410CRITICALA cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 aEPSS 0.8%CVE-2021-21286HIGHAuthorization Bypass in AVideo PlatformEPSS 0.8%CVE-2026-33513HIGHAVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)EPSS 0.7%CVE-2025-53084CRITICALA cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8EPSS 0.7%CVE-2026-41062MEDIUMWWBN/AVideo has an incomplete fix for a directory traversal bypass via query string in ReceiveImage downloadURL parametersEPSS 0.7%CVE-2023-30860HIGHWWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's accountEPSS 0.7%CVE-2026-33292HIGHAVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid VideosEPSS 0.7%CVE-2026-28502CRITICALWWBN AVideo: Authenticated Remote Code Execution via Unsafe Plugin ZIP ExtractionEPSS 0.7%CVE-2026-33037HIGHWWBN AVideo has predictable default admin credentials in official Docker deployment pathEPSS 0.7%