Vulnerabilities > Wwbn > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-01-10 CVE-2023-47171 Unspecified vulnerability in Wwbn Avideo 11.6/15Fed957Fb
An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb.
network
low complexity
wwbn
6.5
2024-01-10 CVE-2023-47861 Cross-site Scripting vulnerability in Wwbn Avideo 11.6/15Fed957Fb
A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb.
network
low complexity
wwbn CWE-79
5.4
2024-01-10 CVE-2023-48728 Cross-site Scripting vulnerability in Wwbn Avideo 11.6/3C6Bb3Ff
A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb3ff.
network
low complexity
wwbn CWE-79
6.1
2024-01-10 CVE-2023-48730 Cross-site Scripting vulnerability in Wwbn Avideo 15Fed957Fb
A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb.
network
low complexity
wwbn CWE-79
5.4
2024-01-10 CVE-2023-49810 Improper Restriction of Excessive Authentication Attempts vulnerability in Wwbn Avideo 15Fed957Fb
A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb.
network
low complexity
wwbn CWE-307
6.5
2024-01-10 CVE-2023-49862 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wwbn Avideo
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb.
network
low complexity
wwbn CWE-610
6.5
2024-01-10 CVE-2023-49863 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wwbn Avideo
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb.
network
low complexity
wwbn CWE-610
6.5
2024-01-10 CVE-2023-49864 Externally Controlled Reference to a Resource in Another Sphere vulnerability in Wwbn Avideo Devmastercommit15Fed957Fb
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit 15fed957fb.
network
low complexity
wwbn CWE-610
6.5
2024-01-10 CVE-2023-50172 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Wwbn Avideo 15Fed957Fb
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb.
network
low complexity
wwbn CWE-640
5.3
2023-05-08 CVE-2023-30860 Cross-site Scripting vulnerability in Wwbn Avideo
WWBN AVideo is an open source video platform.
network
low complexity
wwbn CWE-79
5.4