CVE-2026-87915: Schwachstellen-Eintrag (NVD)
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via values[Name] Parameter in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses sanitization applied on output is insufficient in this context because HTML entities within allowed attribute values survive normalization intact and are later evaluated by the jQuery(link.attr('href')) sink in wp-admin/js/common.js when a contextual help tab anchor is clicked.
- 🔗 plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/A…
- 🔗 plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/A…
- 🔗 plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/L…
- 🔗 plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/N…
- 🔗 plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/N…
- 🔗 plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/N…
- 🔗 plugins.trac.wordpress.org/changeset/3690634/popup-maker/trunk/class…
- 🔗 plugins.trac.wordpress.org/changeset
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-30 | 2026-09-18 |
|---|---|---|
| ≥90 % | 0 | 0 |
| ≥50 % | 0 | 0 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 300 |
CVE-2026-49481 | seriousm4x UpSnap up to 5.3.x Device Management ip/mac os command injection
A vulnerability, which was classified as critical, has been found in seriousm4x UpSnap up to 5.3.x. Affected by this issue is some unknown functionality of the component Device Management. Performing a manipulation of the argument ip/mac re
CVE-2026-49827 | SMEWebify WebErpMesv2 up to 1.19 File Upload scan_file input validation
A vulnerability was found in SMEWebify WebErpMesv2 up to 1.19. It has been rated as critical. This impacts an unknown function of the component File Upload. This manipulation of the argument scan_file causes improper input validation. This
CVE-2026-73291 | seerr-team Seerr up to 3.3.x ImageProxy server/lib/imageproxy.ts path.join path traversal
A vulnerability has been found in seerr-team Seerr up to 3.3.x and classified as critical. Affected by this issue is the function path.join of the file server/lib/imageproxy.ts of the component ImageProxy. Performing a manipulation results
CVE-2026-73296 | Microsoft UFO up to 3.0.7 Mobile MCP Server mobile_mcp_server.py information disclosure (EUVD-2026-57323)
A vulnerability was found in Microsoft UFO up to 3.0.7. It has been declared as problematic. This affects the function create_mobile_data_collection_server/create_mobile_action_server of the file ufo/client/mcp/http_servers/mobile_mcp_serve
CVE-2026-73500 | etcd-io etcd up to 3.5.32/3.6.13/3.7.0 TLS Listener listener_tls.go tls.Conn.Handshake infinite loop
A vulnerability was found in etcd-io etcd up to 3.5.32/3.6.13/3.7.0. It has been classified as problematic. This affects the function tls.Conn.Handshake of the file client/pkg/transport/listener_tls.go of the component TLS Listener. The man
CVE-2026-73501 | getkin kin-openapi up to 0.143.x ValidationHandler validation_handler.go ValidationHandler.Load improper authentication
A vulnerability was found in getkin kin-openapi up to 0.143.x and classified as critical. Affected by this issue is the function ValidationHandler.Load of the file openapi3filter/validation_handler.go of the component ValidationHandler. Exe
CVE-2026-73499 | etcd-io etcd up to 3.5.32/3.6.13/3.7.0 Range Permission Cache range_perm_cache.go isRangeOpPermitted permission
A vulnerability has been found in etcd-io etcd up to 3.5.32/3.6.13/3.7.0 and classified as problematic. Affected by this vulnerability is the function isRangeOpPermitted of the file server/auth/range_perm_cache.go of the component Range Per
CVE-2026-73298 | Microsoft Container Migration Solution Accelerator up to 2.1.2 resource injection
A vulnerability labeled as critical has been found in Microsoft Container Migration Solution Accelerator up to 2.1.2. Affected by this issue is some unknown functionality. Such manipulation leads to improper control of resource identifiers.
CVE-2026-73498 | sooperset mcp-atlassian up to 0.21.x Attachments attachments.py _upload_attachment_direct file_path path traversal
A vulnerability identified as problematic has been detected in sooperset mcp-atlassian up to 0.21.x. This vulnerability affects the function _upload_attachment_direct of the file src/mcp_atlassian/confluence/attachments.py of the component
CVE-2026-73297 | Microsoft UFO up to 3.0.7 url_security.py _is_blocked_ip server-side request forgery (EUVD-2026-57325)
A vulnerability was found in Microsoft UFO up to 3.0.7. It has been rated as critical. This vulnerability affects the function _is_blocked_ip of the file ufo/utils/url_security.py. This manipulation causes server-side request forgery. This
CVE-2026-72925 | swc-project swc/html/swc_html_minifier prior 1.15.47-nightly-20260729.1/59.0.0 MinifyJson Processing lib.rs cross site scripting
A vulnerability classified as problematic has been found in swc-project swc, html and swc_html_minifier. The affected element is an unknown function of the file crates/swc_html_minifier/src/lib.rs of the component MinifyJson Processing. The
CVE-2026-73232 | ffuf up to 2.1.x Response Size Guard pkg/runner/simple.go io.ReadAll resource consumption (EUVD-2026-56926)
A vulnerability categorized as problematic has been discovered in ffuf up to 2.1.x. Affected by this issue is the function io.ReadAll of the file pkg/runner/simple.go of the component Response Size Guard. The manipulation results in resourc
CVE-2026-39452 | Intel Transfer Learning Tool up to 0.6 privileges management
A vulnerability classified as critical has been found in Intel Transfer Learning Tool up to 0.6. Affected by this vulnerability is an unknown functionality. This manipulation causes improper privilege management. This vulnerability is track
CVE-2026-73230 | Ente up to 2026.07.27 2of3 card format missing encryption
A vulnerability categorized as problematic has been discovered in Ente up to 2026.07.27. The impacted element is an unknown function of the component 2of3 card format. The manipulation results in missing encryption of sensitive data. This v
CVE-2026-48802 | miguelgrinberg python-engineio up to 4.13.1 denial of service (Nessus ID 335307)
A vulnerability identified as problematic has been detected in miguelgrinberg python-engineio up to 4.13.1. This issue affects some unknown processing. Performing a manipulation results in denial of service. This vulnerability is known as C
CVE-2026-48809 | miguelgrinberg python-engineio up to 4.13.1 allocation of resources
A vulnerability was found in miguelgrinberg python-engineio up to 4.13.1. It has been rated as problematic. This affects an unknown part. This manipulation causes allocation of resources. This vulnerability appears as CVE-2026-48809. The at
The quiet DoS bug in Cisco's email gateway hardening release
The quiet DoS bug in Cisco's email gateway hardening release Cisco's September 2026 hardening release for its email security appliances covers five CVEs. Four of them are the kind of flaw that draws attention: directory escape, au
When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650
When the Payment-Failure Email Is the Exploit: Inside the Magento Template Rendering Chain of CVE-2026-75650 Opening CVE-2026-75650 is an unauthenticated remote code execution vulnerability in Adobe Commerce and Magento Open Source that rea
CVE-2026-48170 | thomaspoignant scim-patch up to 0.9.0 scimPatch Value prototype pollution
A vulnerability was found in thomaspoignant scim-patch up to 0.9.0. It has been declared as critical. This affects the function scimPatch. The manipulation of the argument Value results in improperly controlled modification of object protot
CVE-2026-48169 | MervinPraison PraisonAI Platform up to 0.1.3 Service Layer workspace_id improper authorization
A vulnerability was found in MervinPraison PraisonAI Platform up to 0.1.3. It has been rated as critical. This impacts an unknown function of the component Service Layer. This manipulation of the argument workspace_id causes improper author
CVE-2026-48161 | dai-shi react18-use Postinstall Script src/install.js permission
A vulnerability, which was classified as critical, was found in dai-shi react18-use. Impacted is an unknown function of the file src/install.js of the component Postinstall Script. The manipulation results in permission issues. This vulnera
CVE-2026-72917 | Mintplex-Labs AnythingLLM up to 1.15.0 Account Recovery index.js recoverAccount recoveryCodes improper authentication
A vulnerability labeled as critical has been found in Mintplex-Labs AnythingLLM up to 1.15.0. Affected is the function recoverAccount of the file server/utils/PasswordRecovery/index.js of the component Account Recovery. The manipulation of
CVE-2026-72904 | Firecrawl up to 2.11.31 Schema Dereferencing dereference-schema.ts path traversal
A vulnerability categorized as problematic has been discovered in Firecrawl up to 2.11.31. This affects an unknown function of the file apps/api/src/lib/extract/helpers/dereference-schema.ts of the component Schema Dereferencing. Executing
CVE-2026-48048 | XWiki prior 16.10.17/17.4.9/17.10.13/18.0.0RC1 LiveTableResults weak password hash
A vulnerability has been found in XWiki and classified as problematic. This impacts an unknown function of the component LiveTableResults. The manipulation leads to password hash with insufficient computational effort. This vulnerability is
CVE-2026-48122 | Shopify ruby-lsp up to 0.10.3 VS Code Extension .vscode/settings.json os command injection (EUVD-2026-54723)
A vulnerability was found in Shopify ruby-lsp up to 0.10.3 and classified as critical. This impacts an unknown function of the file .vscode/settings.json of the component VS Code Extension. The manipulation results in os command injection.
CVE-2026-46409 | OpenYak up to 1.1.2 Desktop Backend cross-domain policy
A vulnerability classified as problematic has been found in OpenYak up to 1.1.2. This issue affects some unknown processing of the component Desktop Backend. This manipulation causes permissive cross-domain policy with untrusted domains. Th
CVE-2026-48047 | XWiki Platform up to 16.10.16/17.4.8/17.10.2 WebJars API path traversal
A vulnerability described as problematic has been identified in XWiki Platform up to 16.10.16/17.4.8/17.10.2. This vulnerability affects unknown code of the component WebJars API. The manipulation results in path traversal. This vulnerabili
CVE-2026-62857 | fedify-dev fedify up to 2.3.1 URL Validation getNodeInfo links[] server-side request forgery
A vulnerability categorized as critical has been discovered in fedify-dev fedify up to 2.3.1. This vulnerability affects the function getNodeInfo of the component URL Validation. Executing a manipulation of the argument links[] can lead to
CVE-2026-71554 | python-hyper h2 up to 4.4.0 request smuggling
A vulnerability was found in python-hyper h2 up to 4.4.0 and classified as problematic. The impacted element is an unknown function. Executing a manipulation can lead to http request smuggling. This vulnerability is handled as CVE-2026-7155
CVE-2026-71476 | Nrwl Nx up to 22.7.6/23.0.1 path traversal
A vulnerability classified as critical was found in Nrwl Nx up to 22.7.6/23.0.1. Affected by this issue is some unknown functionality. Such manipulation leads to path traversal. This vulnerability is referenced as CVE-2026-71476. It is poss
CVE-2026-70646 | vovchic17 aiosend up to 3.0.6 JSON Parsing WebhookHandler.feed_update memory allocation
A vulnerability classified as problematic has been found in vovchic17 aiosend up to 3.0.6. This issue affects the function WebhookHandler.feed_update of the component JSON Parsing. This manipulation causes uncontrolled memory allocation. Th
CVE-2026-65490 | Mediavine Create by Mediavine Plugin up to 2.5.3 on WordPress information disclosure
A vulnerability was found in Mediavine Create by Mediavine Plugin up to 2.5.3 on WordPress. It has been rated as problematic. Affected by this issue is some unknown functionality. This manipulation causes information disclosure. The identif
CVE-2026-22223 | TP-Link Archer BE230 1.2.4 os command injection (EUVD-2026-5086)
A vulnerability categorized as critical has been discovered in TP-Link Archer BE230 1.2.4. This vulnerability affects unknown code. The manipulation results in os command injection. This vulnerability is cataloged as CVE-2026-22223. The att
CVE-2026-22221 | TP-Link Archer BE230 1.2.4 os command injection (EUVD-2026-5100)
A vulnerability was found in TP-Link Archer BE230 1.2.4. It has been declared as critical. Affected by this issue is some unknown functionality. Executing a manipulation can lead to os command injection. This vulnerability is tracked as CVE
CVE-2026-0631 | TP-Link Archer BE230 1.2.4 os command injection (EUVD-2026-5098)
A vulnerability was found in TP-Link Archer BE230 1.2.4. It has been classified as critical. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in os command injection. This vulnerability is identi
Click2Shell-Sicherheitslücke; zeitnah auf WordPress 7.1.1 aktualisieren
Kurze Information: Am 17. September 2026 haben die Entwickler das nächste Wartungsupdate auf 7.1.1. für diese Hauptversion veröffentlicht. Betreiber von WordPress-Sites sollten unverzüglich patchen, da eine Click2Shell-Sicherheitslücke, ges
MikroTik RouterOS CVE-2026-67276: Forged RSA Keys Can Bypass SSH Authentication
MikroTik RouterOS CVE-2026-67276: Forged RSA Keys Can Bypass SSH Authentication CERT-In issued CIVN-2026-0460 on September 16, 2026 with a CRITICAL rating for three MikroTik RouterOS flaws. The most serious of them, CVE-2026-67276, breaks t
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. Weiterlesen
CVE-2026-61591 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restored on reconnect as trusted view state with no integrity check. A client could edit the unsigned `state_json` in their page and return it in the reconnect mount frame to inject arbitrary view attributes — e.g. flip `is_admin
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was restor
CVE-2026-61592 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user — a control the WebSocket transport has but that was dropped on SSE. An attacker who learns (or a victim who leaks) a `session_id` could connect to the message endpoint and dispatch event handlers that execute with the vict
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated user
CVE-2026-61597 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-supplied URL into an `href` / `action` attribute, HTML-escaping it with `conditional_escape` but never validating the URL scheme. HTML escaping prevents attribute breakout but does not neutralize a `javascript:` URI (which n
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/user-s
CVE-2026-92599 | joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO date followed by a long run of fractional-second digits causes the regex engine to restart its search from every position in the string, yielding time proportional to the square of the in
joi (npm package `joi`, hapi.js) versions >=17.2.0 =18.0.0
CVE-2026-92598 | Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addresses with invisible characters or compatibility mappings that pass domain allow-list checks but are delivered to attacker-controlled domains via SMTP.
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can craft recipient addres
CVE-2026-92597 | Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment instead of treating the comment as folding whitespace that terminates the domain. A recipient address such as [email protected](x)evil.com is therefore read by Nodemailer as the single domain good-corp.comevil.com (registr
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surrounding the comment
CVE-2026-92595 | Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using the documented legacy three-argument signature `resolveContent(data, key, callback)`. Because `shared.resolveContent()` normalizes the missing `options` argument to an empty object, the message-level flags copied into `mai
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` using
CVE-2026-92596 | Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a single email with a large number of addresses to block the Node.js event loop for extended periods, consuming 100% CPU and freezing the process.
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a sing
CVE-2026-92594 | Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addresses fields have no per-field authorization. A client holding on
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are ga
CVE-2026-92593 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::elementLabelHtml(). Because Craft/Yii HMAC tokens are not bound to a parameter name, an authenticated low-privilege control panel user with edit rights on a single element type can mint a token over attacker-controlled
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in
CVE-2026-92591 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the configured MySQL endpoint does not. The action accepts a site name, serializes it through Site::getName(), and expands ${NAME} expressions using App::env(). An unauthenticated attacker who obtained
Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP
CVE-2026-92592 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator user (Control Panel access is not required) can set the cookie vi
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound
CVE-2026-92590 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScr
CVE-2026-92589 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that session a `manageNestedElements::<ownerId>::field:<handle>` authorization flag for the entry's Matrix/Address fields. Unlike the corresponding
Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) op
CVE-2026-92588 | n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of from the server-side status computed for the requesting user. An authenticated project-scoped user (e.g., a project admin) could therefore reference files belonging to projects they have no access to and push a deletion of t
n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead of f
CVE-2026-92587 | n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated user (member) who nested the repository one level below the configured path could therefore make an identical UR
n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git wal
CVE-2026-92585 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can submit like and dislike requests to increment vote counters on videos they cannot watch by calling the set.json.php endpoint with APIName parameters.
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can sub
CVE-2026-92586 | AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests to the comment API endpoint with arbitrary video IDs to write comments on videos they cannot watch.
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted videos.
CVE-2026-92584 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings verbatim) directly into the `app` column of the videos_statistics table without invoking the sanitizing setter setApp(); normalizeApp() only truncat
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's Us
CVE-2026-92582 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present in the request; the values are never validated and are read from $_REQUEST, so an attacker can supply them in the query string of a cross-site
AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['b
CVE-2026-92583 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency.
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurre
CVE-2026-92581 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.
In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like