<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:34:16.057311+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277986</id>
    <title>EUVD-2026-277986</title>
    <updated>2026-10-05T21:34:16.059335+00:00</updated>
    <content>EUVD-2026-277986</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-33763</id>
    <title>fkie_cve-2026-33763</title>
    <updated>2026-10-05T21:34:16.059369+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given password is correct for any password-protected video. The endpoint returns a boolean `passwordIsCorrect` field with no rate limiting, CAPTCHA, or authentication requirement, enabling efficient offline-speed brute-force attacks against video passwords. Commit 01a0614fedcdaee47832c0d913a0fb86d8c28135 contains a patch.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-33763"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8prq-2jr2-cm92</id>
    <title>GHSA-8prq-2jr2-cm92 — AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean Oracle</title>
    <updated>2026-10-05T21:34:16.059400+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>The `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given password is correct for any password-protected video. The endpoint returns a boolean `passwordIsCorrect` field with no rate limiting, CAPTCHA, or authentication requirement, enabling efficient offline-speed brute-force attacks against video passwords.</p>
<p>## Details</p>
<p>The vulnerable endpoint is defined at `plugin/API/API.php:1111-1133`:</p>
<p>```php
public function get_api_video_password_is_correct($parameters)
{
    $obj = new stdClass();
    $obj-&gt;videos_id = intval($parameters['videos_id']);
    $obj-&gt;passwordIsCorrect = true;
    $error = true;
    $msg = '';</p>
<p>if (!empty($obj-&gt;videos_id)) {
        $error = false;
        $video = new Video('', '', $obj-&gt;videos_id);
        $password = $video-&gt;getVideo_password();
        if (!empty($password)) {
            $obj-&gt;passwordIsCorrect = $password == $parameters['video_password'];
        }
    } else {
        $msg = 'Videos id is required';
    }</p>
<p>return new ApiObject($msg, $error, $obj);
}
```</p>
<p>The `get()` dispatcher at `API.php:191-209` routes GET requests directly to this method without any authentication enforcement:</p>
<p>```php
public function get($parameters) {
    // ... optional user login if credentials provided ...
    $APIName = $parameters['APIName'];
    if (method_exists($this, "get_api_$APIName")) {
        $str = "\$object = \$this-&gt;get_api_$APIName(\$parameters);";
        eval($str);
    }…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8prq-2jr2-cm92"/>
  </entry>
</feed>
