Please report security issues to developer@streamphp.com
Security: WWBN/AVideo
Security
.github/SECURITY.md
-
Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.phpGHSA-pv87-r9qf-x56p published
Feb 28, 2026 by DanielnetoDotComCritical -
Authenticated Remote Code Execution via Unsafe Plugin ZIP ExtractionGHSA-v8jw-8w5p-23g3 published
Feb 28, 2026 by DanielnetoDotComCritical -
Unauthenticated Password Hash Oracle via encryptPass.json.phpGHSA-px7x-gq96-rmp5 published
Mar 16, 2026 by DanielnetoDotComModerate -
Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORSGHSA-qc3p-398r-p59j published
Mar 16, 2026 by DanielnetoDotComHigh -
Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.phpGHSA-h39h-7cvg-q7j6 published
Feb 23, 2026 by DanielnetoDotComHigh -
Stored Cross-Site Scripting via Markdown Comment InjectionGHSA-rcqw-6466-3mv7 published
Feb 20, 2026 by DanielnetoDotComHigh -
A cross-site scripting (XSS) vulnerability has been identified in the view/about.php page of AVideoGHSA-f98p-2hc5-fm7v published
May 20, 2024 by DanielnetoDotComLow -
command injection vulnerabilityGHSA-2mhh-27v7-3vcx published
May 12, 2023 by DanielnetoDotComHigh -
OS COMMAND INJECTIONGHSA-6vrj-ph27-qfp3 published
Apr 27, 2023 by DanielnetoDotComHigh -
XSSGHSA-2fch-hv74-fgw9 published
Apr 26, 2023 by DanielnetoDotComHigh
Learn more about advisories related to WWBN/AVideo in the GitHub Advisory Database