Security: WWBN/AVideo
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Identification and Authentication Failures: the stored password hash is accepted as the password by two independent paths, so any disclosure of users.password is a direct login with no crackingGHSA-fq38-jp6c-q4cx published
Sep 1, 2026 by DanielnetoDotComCritical -
CloneSite stored shell injection via an unescaped SSH password, plantable by CSRF and fired unattended by the plugin's own cron (residual sink of CVE-2026-41304)GHSA-g96r-pgr6-m7hh published
Sep 1, 2026 by DanielnetoDotComHigh -
Like::__construct() performs the counter arithmetic on the raw request value and validates it only afterwards, so an array-typed parameter desynchronises the stored vote from the counters and drives the public like count arbitrarily negativeGHSA-hcfp-7hrc-5rvg published
Sep 1, 2026 by DanielnetoDotComModerate -
Broken Access Control: objects/videoAddNew.json.php switches off the automatic CSRF guard on the mere presence of two request parameters, before those parameters are validatedGHSA-qf9p-jhx7-rhmf published
Sep 1, 2026 by DanielnetoDotComHigh -
Missing authorization: `APIName=like` records votes on password- and group-restricted videos without `canWatchVideo`GHSA-rrcx-6vw7-xwj8 published
Sep 1, 2026 by DanielnetoDotComModerate -
Missing authorization: `APIName=comment` POST saves comments on password- and group-restricted videos without `canWatchVideo`GHSA-fm4f-q895-8jhc published
Sep 1, 2026 by DanielnetoDotComModerate