Security: WWBN/AVideo
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Session Fixation via GET PHPSESSID Parameter With Disabled Login Session RegenerationGHSA-x3pr-vrhq-vq43 published
Mar 20, 2026 by DanielnetoDotComHigh -
PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl PluginGHSA-6m5f-j7w2-w953 published
Mar 20, 2026 by DanielnetoDotComHigh -
Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name ParameterGHSA-8p58-35c3-ccxx published
Mar 20, 2026 by DanielnetoDotComHigh -
Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.phpGHSA-vv7w-qf5c-734w published
Mar 20, 2026 by DanielnetoDotComHigh -
OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()GHSA-pmj8-r2j7-xg6c published
Mar 20, 2026 by DanielnetoDotComHigh -
SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks ProxyGHSA-p3gr-g84w-g8hh published
Mar 20, 2026 by DanielnetoDotComHigh -
PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against AdminGHSA-xggw-g9pm-9qhh published
Mar 20, 2026 by DanielnetoDotComHigh -
CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin UploadGHSA-hv36-p4w4-6vmj published
Mar 20, 2026 by DanielnetoDotComHigh -
Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command InjectionGHSA-687q-32c6-8x68 published
Mar 20, 2026 by DanielnetoDotComCritical -
Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification BypassGHSA-5f7v-4f6g-74rj published
Mar 19, 2026 by DanielnetoDotComCritical