Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-64626: Server-Side Request Forgery (SSRF) in WWBN AVideoCVE-2026-64626
0

AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing the unpinned retry to follow the redirect and reach internal targets for blind SSRF attacks.

Join the discussion
CVE-2026-55173: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in WWBN AVideoCVE-2026-55173
0

WWBN AVideo versions 29.0 and below are vulnerable to an OS command injection due to incomplete sanitization of special characters in commands executed by the platform. The vulnerability arises because the fix for a prior related issue (CVE-2026-33482) did not neutralize the single ampersand (&) character, which allows chaining multiple commands. This can lead to arbitrary command execution on the standalone encoder server if an attacker can craft a valid encrypted payload. The issue has been addressed in a patch committed to the project's repository.

Join the discussion
CVE-2026-33731: CWE-345: Insufficient Verification of Data Authenticity in WWBN AVideoCVE-2026-33731
0

WWBN AVideo versions prior to 29.0 contain a vulnerability in the Authorize.Net webhook handler that allows attackers to bypass signature verification. This flaw enables forging webhook requests with arbitrary payment amounts and user IDs, resulting in unauthorized wallet credits and activation of premium subscriptions without payment. The issue arises from a combination of signature bypass logic, payload overriding API values, and missing approval checks. The vulnerability has been fixed in version 29.0.

Join the discussion
CVE-2026-33692: CWE-20: Improper Input Validation in WWBN AVideoCVE-2026-33692
0

WWBN AVideo versions prior to 29.0 have a vulnerability where the .env file is exposed to unauthenticated users due to the official Docker compose configuration mounting the project root as the Apache document root. This exposure allows attackers to access sensitive information such as database credentials and admin passwords. The issue is resolved in version 29.0.

Join the discussion
CVE-2026-63305: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in WWBN AVideoCVE-2026-63305
0

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell metacharacters into these fields to execute OS commands as the web-server user.

Join the discussion
CVE-2026-63304: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in WWBN AVideoCVE-2026-63304
0

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can craft a valid encrypted codeToExec payload can break out of the single-quoted grep context and execute arbitrary OS commands as the web-server user.

Join the discussion
CVE-2026-54458: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WWBN AVideoCVE-2026-54458
0

WWBN AVideo versions prior to 29.0 contain a stored DOM-based Cross-Site Scripting (XSS) vulnerability in the YPTSocket plugin. An unauthenticated attacker can inject malicious JavaScript via WebSocket connection parameters, which are broadcast and rendered in the admin dashboard without proper validation. This allows execution of arbitrary scripts in the context of authenticated administrators, leading to full administrative takeover. The vulnerability has been patched in version 29.0.

Join the discussion
CVE-2026-50183: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WWBN AVideoCVE-2026-50183
0

WWBN AVideo versions 29.0 and below contain a stored Cross-Site Scripting (XSS) vulnerability in the YouTubeAPI plugin. The vulnerability arises because the plugin renders the YouTube video title without HTML encoding, treating it as trusted content. An attacker controlling a YouTube video title matching the configured query can inject malicious JavaScript that executes in the browsers of visitors to the AVideo homepage. If the visitor is an administrator, the injected script can perform administrative actions without additional CSRF protection, leading to full administrative takeover. The malicious payload persists for the duration of the cache timeout and can survive removal of the hostile video on YouTube. A fix has been committed but no official patch release information is provided.

Join the discussion
CVE-2026-49279: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in WWBN AVideoCVE-2026-49279
0

WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg'], but msgToResourceId() reads from $msg['json'] with higher priority. An attacker can place the XSS payload in the json key instead of msg, bypassing the sanitization entirely. An authenticated attacker can execute arbitrary JavaScript in any connected user's browser session via the WebSocket messaging system, stealing session cookies and authentication tokens, taking over accounts through session hijacking, and chaining with CSRF to perform admin actions on the victim's behalf, in the default SQLite WebSocket backend configuration. This issue has a patch that has yet to be officially released, see https://github.com/WWBN/AVideo/commit/3e0b3ce2bfa766183ff0ae227439394db57b1a23.

Join the discussion
CVE-2026-33684: CWE-862: Missing Authorization in WWBN AVideoCVE-2026-33684
0

WWBN AVideo versions prior to 29.0 contain a missing authorization vulnerability in the signUp API that allows privilege escalation. Attackers who can solve a CAPTCHA can self-assign elevated permissions such as emailVerified, canUpload, canStream, and canCreateMeet during account registration without proper authentication. This bypasses intended access controls and allows unauthorized capabilities. The issue is fixed in version 29.0.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/wwbn/AVideo
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses