Please report security issues to developer@streamphp.com
Security: WWBN/AVideo
Security
.github/SECURITY.md
-
Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video DeletionGHSA-8x77-f38v-4m5j published
Mar 22, 2026 by DanielnetoDotComHigh -
GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission ModificationGHSA-g8x9-7mgh-7cvj published
Mar 22, 2026 by DanielnetoDotComHigh -
OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File PathGHSA-5m4q-5cvx-36mw published
Mar 22, 2026 by DanielnetoDotComHigh -
Remote Code Execution via MIME/Extension Mismatch in ImageGallery File UploadGHSA-wxjw-phj6-g75w published
Mar 22, 2026 by DanielnetoDotComHigh -
Unauthenticated SSRF via plugin/Live/test.phpGHSA-3fpm-8rjr-v5mc published
Mar 20, 2026 by DanielnetoDotComCritical -
Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions PluginGHSA-96qp-8cmq-jvq8 published
Mar 20, 2026 by DanielnetoDotComModerate -
Incomplete Fix for CVE-2026-27568: Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWithLinks SanitizationGHSA-72h5-39r7-r26j published
Mar 20, 2026 by DanielnetoDotComModerate -
Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPage.phpGHSA-7292-w8qp-mhq2 published
Mar 20, 2026 by DanielnetoDotComModerate -
Path Traversal in import.json.php Allows Private Video Theft and Arbitrary File Read/Deletion via fileURI ParameterGHSA-83xq-8jxj-4rxm published
Mar 20, 2026 by DanielnetoDotComHigh -
Session Fixation via GET PHPSESSID Parameter With Disabled Login Session RegenerationGHSA-x3pr-vrhq-vq43 published
Mar 20, 2026 by DanielnetoDotComHigh
Learn more about advisories related to WWBN/AVideo in the GitHub Advisory Database