wwbn avideo
184 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
cloneServer.json.php endpoint in the CloneSite plutest.php addsisValidDuration() regex at objects/video.php:918isSSRFSafeURL() function in `objects/functions.phpdeleteDump p986e64aad isallowOrigin($allowAll=true) function in `objects/fobjects/getCaptcha.php accepts the CAPTCHA length (`qlobjects/commentDelete.json.php is a state-mutating JSOobjects/ accept sobjects/configurationUpdate.json.php (also routed vialocale/save.php) constructsgit.json.php at the web root executes `git loLive_schedule::keyExists() method constrget_api_video_file and get_api_video AtransferBalance() method in `plugin/YPTWcategories.json.php endpoint, which servverifyTokenSocket() function in `plugin/plugin/Live/uploadPoster.php endpoint alfixCleanTitle() static method in `objectobjects/like.php, the getLike() methodisSSRFSafeURL() validates URLs against privasave.json.php endpoint loadsget_api_video_password_is_correct API enlist.json.php endpoints in the Schedulobjects/playlistsVideos.json.php endpoinSubscribe::save() method in `objects/subdownloadVideoFromDownloadURL() functiongetRealIpAddr() function in `objects/funplugin/AD_Server/reports.json.php endpoiobjects/pluginRunDatabaseScript.json.phpremindMe.json.php endpoint passes `$_REQImageGallery::saveFile() method validatedecryptString actioobjects/pluginImport.json.php endpoint aview/forbiddenPage.php and `view/warningobjects/import.json.php endpoint accepts_session_start() function accepts acreateKeys() function in the LoginControon_publish callback at `plugin/LiveaVideoEncoderChunk.json.php endpoint issanitizeFFmpegCommand() function in `pluisSSRFSafeURL() function in AVideo can bsaveSort.json.php endpoPOST /objects/aVideoEncoder.json.php acceptssetPassword.json.php endpoint in the CustomizeUser pluguploadVideoToLinkedIn() method in the SocialMediaPublisdeleteDump parameter in `plugin/CloneSite/cloneServer.jview/hls.php) is vulnerable tolistFiles.json.php endpoint accepts a path POST paramrun() function in `plugin/Scheduler/aVideoEncoder.json.php API endpoint accepts a `download