Please report security issues to developer@streamphp.com
Security: WWBN/AVideo
Security
.github/SECURITY.md
-
Stored XSS via unescaped Gallery category descriptionGHSA-c8h8-vq34-9fw2 published
May 19, 2026 by DanielnetoDotComModerate -
Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`GHSA-w4qq-74h6-58wq published
May 13, 2026 by DanielnetoDotComModerate -
Authenticated Arbitrary File Read in view/update.phpGHSA-3mjv-375j-6h92 published
May 12, 2026 by DanielnetoDotComModerate -
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`GHSA-vpfx-pxqw-2w79 published
May 11, 2026 by DanielnetoDotComModerate -
AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`GHSA-c3ch-22rq-xfwr published
May 11, 2026 by DanielnetoDotComModerate -
plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FAGHSA-3mv2-vmwh-rwfx published
May 11, 2026 by DanielnetoDotComModerate -
Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attributeGHSA-m5j4-7r85-2cj2 published
May 11, 2026 by DanielnetoDotComModerate -
Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URLGHSA-xw67-cg5f-4m2r published
May 11, 2026 by DanielnetoDotComHigh -
Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including adminGHSA-qxvm-r42f-5p8j published
May 11, 2026 by DanielnetoDotComHigh -
Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization in WWBN/AVideoGHSA-xr49-f4rh-qcjf published
Apr 27, 2026 by DanielnetoDotComHigh
Learn more about advisories related to WWBN/AVideo in the GitHub Advisory Database