Security: WWBN/AVideo
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)GHSA-mcj5-6qr4-95fj published
Mar 19, 2026 by DanielnetoDotComCritical -
Authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`GHSA-4jw9-5hrc-m4j6 published
Mar 19, 2026 by DanielnetoDotComHigh -
IDOR - Any Admin Can Set Another User's Channel Password via setPassword.json.phpGHSA-6547-8hrg-c55m published
Mar 18, 2026 by DanielnetoDotComModerate -
Open Redirect via Unvalidated redirectUri in userLogin.phpGHSA-hj5h-5623-gwhw published
Mar 18, 2026 by DanielnetoDotComModerate -
Stored XSS via Unescaped Video Title in CDN downloadButtons.phpGHSA-gc3m-4mcr-h3pv published
Mar 18, 2026 by DanielnetoDotComHigh -
Unauthenticated PGP Message Decryption via Public EndpointGHSA-5x2w-37xf-7962 published
Mar 18, 2026 by DanielnetoDotComModerate -
OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell CommandGHSA-w5ff-2mjc-4phc published
Mar 18, 2026 by DanielnetoDotComModerate -
Arbitrary File Deletion via Path Traversal in CloneSite deleteDump ParameterGHSA-xmjm-86qv-g226 published
Mar 18, 2026 by DanielnetoDotComHigh -
SSRF in BulkEmbed Thumbnail Fetch Allows Reading Internal Network ResourcesGHSA-66cw-h2mj-j39p published
Mar 18, 2026 by DanielnetoDotComModerate -
Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid VideosGHSA-pw4v-x838-w5pg published
Mar 18, 2026 by DanielnetoDotComHigh