📦 Avideo

by Wwbn

🔍 What is Avideo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34434

CRITICAL CVSS 9.1 Dec 17, 2025

AVideo versions before 20.1 with the ImageGallery plugin enabled are vulnerable to unauthenticated file upload and deletion. Attackers can upload malicious files or delete images from any image-based ...

CVE-2025-50128

CRITICAL CVSS 9.6 Jul 24, 2025

A stored cross-site scripting vulnerability in WWBN AVideo allows attackers to inject malicious JavaScript via the videoNotFound 404ErrorMsg parameter. When users visit a specially crafted webpage, ar...

CVE-2025-41420

CRITICAL CVSS 9.6 Jul 24, 2025

A cross-site scripting vulnerability in WWBN AVideo's userLogin cancelUri parameter allows attackers to execute arbitrary JavaScript when users visit malicious webpages. This affects WWBN AVideo 14.4 ...

CVE-2023-49599

CRITICAL CVSS 9.8 Jan 10, 2024

This vulnerability allows attackers to forge password recovery codes for admin users in WWBN AVideo by exploiting weak salt generation. Attackers can brute-force the salt offline after gathering syste...

CVE-2023-47861

CRITICAL CVSS 9.0 Jan 10, 2024

A cross-site scripting vulnerability in WWBN AVideo's channelBody.php allows attackers to inject malicious JavaScript via user name input. When exploited, this enables arbitrary script execution in vi...

CVE-2023-48728

CRITICAL CVSS 9.6 Jan 10, 2024

This is a stored cross-site scripting (XSS) vulnerability in WWBN AVideo's getOpenGraph videoName functionality that allows attackers to inject malicious JavaScript. When exploited, it enables arbitra...

CVE-2020-37173

HIGH CVSS 7.5 Feb 11, 2026

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.json.php endpoint. By manipulating the users_id param...

CVE-2025-34436

HIGH CVSS 8.8 Dec 17, 2025

AVideo versions before 20.1 contain an insecure direct object reference vulnerability that allows any authenticated user to upload files into other users' directories. This occurs because the upload f...

CVE-2025-34437

HIGH CVSS 8.8 Dec 17, 2025

This vulnerability allows any authenticated user to upload comment images to videos owned by other users in AVideo. Attackers can perform unauthorized uploads to arbitrary video objects due to missing...

CVE-2025-34438

HIGH CVSS 8.1 Dec 17, 2025

AVideo versions before 20.1 contain an insecure direct object reference vulnerability that allows authenticated users with upload permissions to modify rotation metadata of any video in the system, re...

CVE-2025-34441

HIGH CVSS 7.5 Dec 17, 2025

AVideo versions before 20.1 expose sensitive user information through an unauthenticated public API endpoint. This allows attackers to enumerate users, obtain emails, usernames, administrative status,...

CVE-2025-34442

HIGH CVSS 7.5 Dec 17, 2025

AVideo versions before 20.1 expose absolute server filesystem paths through public API endpoints. This information disclosure vulnerability reveals internal directory structures, which attackers can l...

CVE-2025-48732

HIGH CVSS 7.3 Jul 24, 2025

An incomplete blacklist in WWBN AVideo's .htaccess sample allows attackers to execute arbitrary code by requesting specially crafted .phar files. This affects WWBN AVideo 14.4 and development versions...

CVE-2025-25214

HIGH CVSS 8.8 Jul 24, 2025

A race condition vulnerability in WWBN AVideo's aVideoEncoder.json.php unzip functionality allows attackers to execute arbitrary code through specially crafted HTTP requests. This affects AVideo 14.4 ...

CVE-2023-49589

HIGH CVSS 8.8 Jan 10, 2024

This vulnerability allows attackers to reset arbitrary user passwords in WWBN AVideo by exploiting insufficient entropy in password recovery token generation. Attackers can send crafted HTTP requests ...

CVE-2023-49738

HIGH CVSS 7.5 Jan 10, 2024

This vulnerability allows attackers to read arbitrary files on WWBN AVideo servers by exploiting improper input validation in the image404Raw.php script. It affects WWBN AVideo installations running d...

CVE-2023-30860

HIGH CVSS 8.0 May 8, 2023

This is a stored cross-site scripting (XSS) vulnerability in WWBN AVideo's meeting scheduling feature. Attackers can inject malicious scripts into meeting rooms that execute when viewed by other users...

CVE-2020-37158

MEDIUM CVSS 5.3 Feb 11, 2026

CVE-2020-37158 is a CSRF vulnerability in AVideo Platform 8.1 that allows attackers to reset user passwords without authentication by exploiting the password recovery mechanism. Attackers can craft ma...

CVE-2025-34439

MEDIUM CVSS 6.1 Dec 17, 2025

AVideo versions before 20.1 contain an open redirect vulnerability in the login functionality. Attackers can craft malicious links that redirect users to arbitrary external websites after login, enabl...

CVE-2025-34440

MEDIUM CVSS 6.1 Dec 17, 2025

AVideo versions before 20.1 contain an open redirect vulnerability in the user registration process. Attackers can manipulate the siteRedirectUri parameter to redirect users to malicious external webs...

CVE-2025-34435

MEDIUM CVSS 6.5 Dec 17, 2025

AVideo versions before 20.1 contain an insecure direct object reference (IDOR) vulnerability that allows any authenticated user to delete media files belonging to other users. The vulnerability occurs...