{"schema_version":1,"title":"wwbn/avideo (Packagist) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 169 vulnerabilities in wwbn/avideo (Packagist): 0 in the last 7 days and 9 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55173, was published on 16 July 2026.","url":"https://junglewise.ai/threats/technologies/wwbn-avideo","json_url":"https://junglewise.ai/threats/technologies/wwbn-avideo.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/wwbn-avideo","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":23,"all_time":169,"critical":6,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":155},"latest":[{"cve":"CVE-2026-55173","cvss":8.1,"epss":0.0343,"slug":"cve-2026-55173-wwbn-avideo-os-command-injection-in-sanitizeffmpegcommand","title":"WWBN AVideo OS command injection in sanitizeFFmpegCommand","severity":"high","exploited":false,"published_at":"2026-07-16T21:17:21.483+00:00","url":"https://junglewise.ai/threats/cve-2026-55173-wwbn-avideo-os-command-injection-in-sanitizeffmpegcommand"},{"cve":"CVE-2026-33731","cvss":6.5,"epss":0.0021,"slug":"cve-2026-33731-wwbn-avideo-signature-verification-bypass-in-authorize-net","title":"WWBN AVideo signature verification bypass in Authorize.Net webhook","severity":"medium","exploited":false,"published_at":"2026-07-16T21:17:20.317+00:00","url":"https://junglewise.ai/threats/cve-2026-33731-wwbn-avideo-signature-verification-bypass-in-authorize-net"},{"cve":"CVE-2026-33692","cvss":7.5,"epss":0.0045,"slug":"cve-2026-33692-wwbn-avideo-sensitive-information-disclosure-in-docker","title":"WWBN AVideo sensitive information disclosure in Docker configuration","severity":"high","exploited":false,"published_at":"2026-07-16T21:17:20.183+00:00","url":"https://junglewise.ai/threats/cve-2026-33692-wwbn-avideo-sensitive-information-disclosure-in-docker"},{"cve":"CVE-2026-54458","cvss":9.6,"epss":0.0051,"slug":"cve-2026-54458-wwbn-avideo-stored-dom-xss-in-yptsocket-plugin","title":"WWBN AVideo stored DOM XSS in YPTSocket plugin","severity":"critical","exploited":false,"published_at":"2026-07-15T22:17:19.16+00:00","url":"https://junglewise.ai/threats/cve-2026-54458-wwbn-avideo-stored-dom-xss-in-yptsocket-plugin"},{"cve":"CVE-2026-50183","cvss":4.7,"epss":0.0026,"slug":"cve-2026-50183-wwbn-avideo-stored-xss-in-youtubeapi-plugin","title":"WWBN AVideo stored XSS in YouTubeAPI plugin","severity":"medium","exploited":false,"published_at":"2026-07-15T22:16:54.643+00:00","url":"https://junglewise.ai/threats/cve-2026-50183-wwbn-avideo-stored-xss-in-youtubeapi-plugin"},{"cve":"CVE-2026-50182","cvss":6.1,"epss":0.0029,"slug":"cve-2026-50182-wwbn-avideo-reflected-xss-in-youtubeapi-gallery-pagination","title":"WWBN AVideo reflected XSS in YouTubeAPI gallery pagination","severity":"medium","exploited":false,"published_at":"2026-07-15T22:16:54.507+00:00","url":"https://junglewise.ai/threats/cve-2026-50182-wwbn-avideo-reflected-xss-in-youtubeapi-gallery-pagination"},{"cve":"CVE-2026-49279","cvss":4,"epss":0.0054,"slug":"cve-2026-49279-wwbn-avideo-stored-xss-in-messagesqlite-websocket-handler","title":"WWBN AVideo Stored XSS in MessageSQLite WebSocket handler","severity":"high","exploited":false,"published_at":"2026-07-15T22:16:52.163+00:00","url":"https://junglewise.ai/threats/cve-2026-49279-wwbn-avideo-stored-xss-in-messagesqlite-websocket-handler"},{"cve":"CVE-2026-33684","cvss":5.3,"epss":0.0033,"slug":"cve-2026-33684-wwbn-avideo-privilege-escalation-in-signup-api","title":"WWBN AVideo privilege escalation in signUp API","severity":"medium","exploited":false,"published_at":"2026-07-15T21:16:36.323+00:00","url":"https://junglewise.ai/threats/cve-2026-33684-wwbn-avideo-privilege-escalation-in-signup-api"},{"cve":"CVE-2026-60092","cvss":6.1,"epss":0.0035,"slug":"cve-2026-60092-wwbn-avideo-meet-plugin-stored-xss-via-user-agent-header","title":"WWBN AVideo Meet plugin stored XSS via User-Agent header","severity":"medium","exploited":false,"published_at":"2026-07-08T14:17:22.37+00:00","url":"https://junglewise.ai/threats/cve-2026-60092-wwbn-avideo-meet-plugin-stored-xss-via-user-agent-header"},{"slug":"wwbn-avideo-meet-plugin-stored-xss-in-participants-panel-via-user-agent-9dbd106b","title":"WWBN AVideo Meet plugin stored XSS in Participants panel via User-Agent","severity":"medium","exploited":false,"published_at":"2026-06-23T19:11:27+00:00","url":"https://junglewise.ai/threats/wwbn-avideo-meet-plugin-stored-xss-in-participants-panel-via-user-agent-9dbd106b"},{"cvss":3.1,"slug":"duplicate-advisory-avideo-has-unauthenticated-pgp-message-decryption-b79918cf","title":"Duplicate Advisory: AVideo has Unauthenticated PGP Message Decryption via Public Endpoint","severity":"low","exploited":false,"published_at":"2026-06-20T21:31:22+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-avideo-has-unauthenticated-pgp-message-decryption-b79918cf"},{"cvss":6.5,"slug":"avideo-unauthenticated-pgp-message-decryption-in-decryptmessage-ed490c51","title":"AVideo unauthenticated PGP message decryption in decryptMessage endpoint","severity":"medium","exploited":false,"published_at":"2026-06-20T21:31:22+00:00","url":"https://junglewise.ai/threats/avideo-unauthenticated-pgp-message-decryption-in-decryptmessage-ed490c51"},{"cvss":3.1,"slug":"duplicate-advisory-avideo-unauthenticated-access-to-payment-log-8b3ee961","title":"Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Fin","severity":"low","exploited":false,"published_at":"2026-06-20T21:31:21+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-avideo-unauthenticated-access-to-payment-log-8b3ee961"},{"cvss":7.5,"slug":"avideo-unauthenticated-access-to-payment-endpoints-24447c77","title":"AVideo unauthenticated access to payment endpoints","severity":"high","exploited":false,"published_at":"2026-06-20T21:31:21+00:00","url":"https://junglewise.ai/threats/avideo-unauthenticated-access-to-payment-endpoints-24447c77"},{"cve":"CVE-2026-56347","cvss":6.1,"epss":0.0026,"slug":"cve-2026-56347-wwbn-avideo-topmenu-plugin-stored-xss-in-menu-rendering","title":"WWBN AVideo TopMenu plugin stored XSS in menu rendering","severity":"medium","exploited":false,"published_at":"2026-06-20T19:16:24.267+00:00","url":"https://junglewise.ai/threats/cve-2026-56347-wwbn-avideo-topmenu-plugin-stored-xss-in-menu-rendering"},{"cve":"CVE-2026-56346","cvss":6.5,"epss":0.0062,"slug":"cve-2026-56346-wwbn-avideo-authentication-bypass-in-decryptmessage-json-php","title":"WWBN AVideo authentication bypass in decryptMessage.json.php","severity":"medium","exploited":false,"published_at":"2026-06-20T19:16:24.127+00:00","url":"https://junglewise.ai/threats/cve-2026-56346-wwbn-avideo-authentication-bypass-in-decryptmessage-json-php"},{"cve":"CVE-2026-56345","cvss":8.1,"epss":0.0045,"slug":"cve-2026-56345-wwbn-avideo-authorization-bypass-in-meet-plugin","title":"WWBN AVideo authorization bypass in Meet plugin","severity":"high","exploited":false,"published_at":"2026-06-20T19:16:23.983+00:00","url":"https://junglewise.ai/threats/cve-2026-56345-wwbn-avideo-authorization-bypass-in-meet-plugin"},{"cve":"CVE-2026-56341","cvss":7.5,"epss":0.0046,"slug":"cve-2026-56341-avideo-missing-authorization-in-multiple-plugin-list-endpoints","title":"AVideo missing authorization in multiple plugin list endpoints","severity":"high","exploited":false,"published_at":"2026-06-20T19:16:23.7+00:00","url":"https://junglewise.ai/threats/cve-2026-56341-avideo-missing-authorization-in-multiple-plugin-list-endpoints"},{"cvss":9.6,"slug":"wwbn-avideo-unauthenticated-stored-dom-xss-in-yptsocket-plugin-227d9154","title":"WWBN AVideo unauthenticated stored DOM XSS in YPTSocket plugin","severity":"critical","exploited":false,"published_at":"2026-06-04T18:57:50+00:00","url":"https://junglewise.ai/threats/wwbn-avideo-unauthenticated-stored-dom-xss-in-yptsocket-plugin-227d9154"},{"cve":"CVE-2026-47696","cvss":4.3,"epss":0.0015,"slug":"cve-2026-47696-wwbn-avideo-insufficient-verification-in-authorizenet-plugin","title":"WWBN AVideo insufficient verification in AuthorizeNet plugin","severity":"medium","exploited":false,"published_at":"2026-05-29T14:16:32.127+00:00","url":"https://junglewise.ai/threats/cve-2026-47696-wwbn-avideo-insufficient-verification-in-authorizenet-plugin"},{"cve":"CVE-2026-47694","cvss":5.4,"epss":0.0024,"slug":"cve-2026-47694-wwbn-avideo-stored-xss-in-category-description","title":"WWBN AVideo stored XSS in category description","severity":"medium","exploited":false,"published_at":"2026-05-29T14:16:31.997+00:00","url":"https://junglewise.ai/threats/cve-2026-47694-wwbn-avideo-stored-xss-in-category-description"},{"cve":"CVE-2026-46337","cvss":3.1,"epss":0.0058,"slug":"cve-2026-46337-wwbn-avideo-path-traversal-in-image404raw-php","title":"WWBN AVideo path traversal in image404Raw.php","severity":"medium","exploited":false,"published_at":"2026-05-29T14:16:31.52+00:00","url":"https://junglewise.ai/threats/cve-2026-46337-wwbn-avideo-path-traversal-in-image404raw-php"},{"cve":"CVE-2026-45731","cvss":3.1,"epss":0.0059,"slug":"cve-2026-45731-wwbn-avideo-path-traversal-in-view-update-php","title":"WWBN AVideo path traversal in view/update.php","severity":"medium","exploited":false,"published_at":"2026-05-29T14:16:31.383+00:00","url":"https://junglewise.ai/threats/cve-2026-45731-wwbn-avideo-path-traversal-in-view-update-php"},{"cve":"CVE-2026-45620","cvss":5.3,"epss":0.0032,"slug":"cve-2026-45620-wwbn-avideo-unauthenticated-user-enumeration-in-mention-json-php","title":"WWBN AVideo unauthenticated user enumeration in mention.json.php","severity":"medium","exploited":false,"published_at":"2026-05-29T14:16:31.107+00:00","url":"https://junglewise.ai/threats/cve-2026-45620-wwbn-avideo-unauthenticated-user-enumeration-in-mention-json-php"},{"cve":"CVE-2026-45619","cvss":6.5,"epss":0.0021,"slug":"cve-2026-45619-wwbn-avideo-ssrf-via-dns-rebinding-toctou","title":"WWBN AVideo SSRF via DNS-rebinding TOCTOU","severity":"medium","exploited":false,"published_at":"2026-05-29T14:16:30.98+00:00","url":"https://junglewise.ai/threats/cve-2026-45619-wwbn-avideo-ssrf-via-dns-rebinding-toctou"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":8},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"getgrav/grav (Packagist)","slug":"getgrav-grav","vulnerabilities":63,"url":"https://junglewise.ai/threats/technologies/getgrav-grav"},{"name":"concrete5/concrete5 (Packagist)","slug":"concrete5-concrete5","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/concrete5-concrete5"},{"name":"snipe/snipe-it (Packagist)","slug":"snipe-snipe-it","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/snipe-snipe-it"},{"name":"thorsten/phpmyfaq (Packagist)","slug":"thorsten-phpmyfaq","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/thorsten-phpmyfaq"},{"name":"phpmyfaq/phpmyfaq (Packagist)","slug":"phpmyfaq-phpmyfaq","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/phpmyfaq-phpmyfaq"},{"name":"craftcms/cms (Packagist)","slug":"craftcms-cms","vulnerabilities":27,"url":"https://junglewise.ai/threats/technologies/craftcms-cms"},{"name":"mantisbt/mantisbt (Packagist)","slug":"mantisbt-mantisbt","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/mantisbt-mantisbt"},{"name":"kimai/kimai (Packagist)","slug":"kimai-kimai","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/kimai-kimai"},{"name":"froxlor/froxlor (Packagist)","slug":"froxlor-froxlor","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/froxlor-froxlor"},{"name":"yeswiki/yeswiki (Packagist)","slug":"yeswiki-yeswiki","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/yeswiki-yeswiki"},{"name":"twig/twig (Packagist)","slug":"twig-twig","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/twig-twig"},{"name":"shopper/framework (Packagist)","slug":"shopper-framework","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/shopper-framework"}],"technology":{"hub":true,"name":"wwbn/avideo (Packagist)","slug":"wwbn-avideo","vendor":{"name":"Packagist","slug":"packagist","url":"https://junglewise.ai/threats/vendors/packagist"},"aliases":[],"homepage":"https://avideo.com/","repo_url":"https://github.com/WWBN/AVideo","description":"An open-source video platform for creating and managing video sharing websites.","url":"https://junglewise.ai/threats/technologies/wwbn-avideo"},"most_severe":[{"cve":"CVE-2026-40911","cvss":10,"epss":0.0086,"slug":"cve-2026-40911-wwbn-avideo-yptsocket-websocket-broadcast-relay-leads-to","title":"WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks","severity":"critical","exploited":false,"published_at":"2026-04-14T22:50:05+00:00","url":"https://junglewise.ai/threats/cve-2026-40911-wwbn-avideo-yptsocket-websocket-broadcast-relay-leads-to"},{"cve":"CVE-2026-41304","cvss":9.8,"epss":0.0269,"slug":"cve-2026-41304-wwbn-avideo-rce-cause-by-clonesite-plugin","title":"WWBN AVideo: RCE cause by clonesite plugin","severity":"critical","exploited":false,"published_at":"2026-04-16T21:25:19+00:00","url":"https://junglewise.ai/threats/cve-2026-41304-wwbn-avideo-rce-cause-by-clonesite-plugin"},{"cve":"CVE-2023-25313","cvss":9.6,"epss":0.0132,"slug":"cve-2023-25313-wwbn-avideo-command-injection-in-video-embedding","title":"WWBN AVideo command injection in video embedding","severity":"critical","exploited":false,"published_at":"2023-02-02T01:32:42+00:00","url":"https://junglewise.ai/threats/cve-2023-25313-wwbn-avideo-command-injection-in-video-embedding"},{"cve":"CVE-2026-54458","cvss":9.6,"epss":0.0051,"slug":"cve-2026-54458-wwbn-avideo-stored-dom-xss-in-yptsocket-plugin","title":"WWBN AVideo stored DOM XSS in YPTSocket plugin","severity":"critical","exploited":false,"published_at":"2026-07-15T22:17:19.16+00:00","url":"https://junglewise.ai/threats/cve-2026-54458-wwbn-avideo-stored-dom-xss-in-yptsocket-plugin"},{"cvss":9.6,"slug":"wwbn-avideo-unauthenticated-stored-dom-xss-in-yptsocket-plugin-227d9154","title":"WWBN AVideo unauthenticated stored DOM XSS in YPTSocket plugin","severity":"critical","exploited":false,"published_at":"2026-06-04T18:57:50+00:00","url":"https://junglewise.ai/threats/wwbn-avideo-unauthenticated-stored-dom-xss-in-yptsocket-plugin-227d9154"},{"cve":"CVE-2026-41064","cvss":9.3,"epss":0.0047,"slug":"cve-2026-41064-wwbn-avideo-has-an-incomplete-fix-for-command-injection","title":"WWBN AVideo has an incomplete fix for : Command Injection","severity":"critical","exploited":false,"published_at":"2026-04-14T23:27:18+00:00","url":"https://junglewise.ai/threats/cve-2026-41064-wwbn-avideo-has-an-incomplete-fix-for-command-injection"},{"cve":"CVE-2026-45578","cvss":8.8,"epss":0.0053,"slug":"cve-2026-45578-wwbn-avideo-os-command-injection-in-live-plugin","title":"WWBN AVideo OS command injection in Live plugin","severity":"high","exploited":false,"published_at":"2026-05-29T14:16:30.253+00:00","url":"https://junglewise.ai/threats/cve-2026-45578-wwbn-avideo-os-command-injection-in-live-plugin"},{"cve":"CVE-2026-40909","cvss":8.7,"epss":0.0082,"slug":"cve-2026-40909-wwbn-avideo-has-a-path-traversal-in-locale-save-endpoint-enables","title":"WWBN AVideo has a Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)","severity":"high","exploited":false,"published_at":"2026-04-14T22:49:48+00:00","url":"https://junglewise.ai/threats/cve-2026-40909-wwbn-avideo-has-a-path-traversal-in-locale-save-endpoint-enables"},{"cve":"CVE-2026-40925","cvss":8.3,"epss":0.002,"slug":"cve-2026-40925-wwbn-avideo-has-csrf-in-configurationupdate-json-php-enables-full","title":"WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials","severity":"high","exploited":false,"published_at":"2026-04-14T23:12:30+00:00","url":"https://junglewise.ai/threats/cve-2026-40925-wwbn-avideo-has-csrf-in-configurationupdate-json-php-enables-full"},{"cve":"CVE-2026-55173","cvss":8.1,"epss":0.0343,"slug":"cve-2026-55173-wwbn-avideo-os-command-injection-in-sanitizeffmpegcommand","title":"WWBN AVideo OS command injection in sanitizeFFmpegCommand","severity":"high","exploited":false,"published_at":"2026-07-16T21:17:21.483+00:00","url":"https://junglewise.ai/threats/cve-2026-55173-wwbn-avideo-os-command-injection-in-sanitizeffmpegcommand"}],"generated_at":"2026-09-26T20:07:00.238639+00:00"}