CVE-2026-34395: Wwbn Avideo

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks User::isLogged() but does not check User::isAdmin(), so any registered user can dump the full user database. At time of publication, there are no publicly available patches.

Affected products

  • Wwbn Avideo: up to and including 26.0

Published 2026-03-31. Last modified 2026-07-24.