Please report security issues to developer@streamphp.com
Security: WWBN/AVideo
Security
.github/SECURITY.md
-
CORS Origin Reflection with Credentials on Sensitive API Endpoints Enables Cross-Origin Account TakeoverGHSA-ccq9-r5cw-5hwq published
Apr 13, 2026 by DanielnetoDotComHigh -
Incomplete fix for CVE-2026-33039: SSRF in AVideoGHSA-793q-xgj6-7frp published
Apr 13, 2026 by DanielnetoDotComModerate -
CAPTCHA Bypass in WWBN/AVideo via Attacker-Controlled Length Parameter and Missing Token Invalidation on FailureGHSA-hg7g-56h5-5pqr published
Apr 13, 2026 by DanielnetoDotComModerate -
Missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creatorsGHSA-8qm8-g55h-xmqr published
Apr 13, 2026 by DanielnetoDotComModerate -
AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset DeletionGHSA-x2pw-9c38-cp2j published
Apr 13, 2026 by DanielnetoDotComModerate -
Multiple CSRF Vulnerabilities in Admin JSON Endpoints (Category CRUD, Plugin Update Script)GHSA-ffw8-fwxp-h64w published
Apr 13, 2026 by DanielnetoDotComHigh -
CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP CredentialsGHSA-vvfw-4m39-fjqf published
Apr 13, 2026 by DanielnetoDotComHigh -
AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() SinksGHSA-gph2-j4c9-vhhr published
Apr 13, 2026 by DanielnetoDotComCritical -
Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)GHSA-6rc6-p838-686f published
Apr 13, 2026 by DanielnetoDotComHigh -
Unauthenticated Information Disclosure via git.json.php Exposes Developer Emails and Deployed VersionGHSA-52hf-63q4-r926 published
Apr 13, 2026 by DanielnetoDotComModerate
Learn more about advisories related to WWBN/AVideo in the GitHub Advisory Database