Please report security issues to developer@streamphp.com
Security: WWBN/AVideo
Security
.github/SECURITY.md
-
WWBN AVideo through 29.2.0 Stored XSS via Video trailer1 in YouPHPFlix2 TemplatesGHSA-6wfr-c7fw-4xvw published
Oct 4, 2026 by DanielnetoDotComHigh -
WWBN AVideo through 29.2.0 Stored XSS via Double-Encoded Video TitleGHSA-q62w-927x-vhhf published
Oct 4, 2026 by DanielnetoDotComHigh -
Stored XSS in video trailer1 field via HTML-entity bypass of isValidurl()GHSA-v7vx-v9q9-qhw3 published
Sep 11, 2026 by DanielnetoDotComModerate -
Use of a cryptographically weak PRNG: RTMP publish keys are raw `uniqid()` values derived from the transmission creation timeGHSA-h983-2mcw-672j published
Sep 2, 2026 by DanielnetoDotComModerate -
Use of a cryptographically weak PRNG: `getRandomCode()` activation codes are a pure function of server microtime, and redeeming one returns a one-year authentication tokenGHSA-v65f-hc7x-wj62 published
Sep 2, 2026 by DanielnetoDotComHigh -
Identification and Authentication Failures: LoginControl's PGP second factor is satisfied by a single parameter-less GET, because the challenge is compared with == against a session value that is unset until the challenge page is renderedGHSA-mvmf-jqg6-qhjf published
Sep 2, 2026 by DanielnetoDotComHigh -
Identification and Authentication Failures: the stored password hash is accepted as the password by two independent paths, so any disclosure of users.password is a direct login with no crackingGHSA-fq38-jp6c-q4cx published
Sep 1, 2026 by DanielnetoDotComCritical -
CloneSite stored shell injection via an unescaped SSH password, plantable by CSRF and fired unattended by the plugin's own cron (residual sink of CVE-2026-41304)GHSA-g96r-pgr6-m7hh published
Sep 1, 2026 by DanielnetoDotComHigh
Learn more about advisories related to WWBN/AVideo in the GitHub Advisory Database