youphptube CVE Vulnerabilities & Metrics

Focus on youphptube vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About youphptube Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with youphptube. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total youphptube CVEs: 21
Earliest CVE date: 20 Aug 2019, 14:15 UTC
Latest CVE date: 01 Nov 2021, 12:15 UTC

Latest CVE reference: CVE-2021-25878

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical youphptube CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.6

Max CVSS: 9.3

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 13
7.0-8.9 6
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS youphptube CVEs

These are the five CVEs with the highest CVSS scores for youphptube, sorted by severity first and recency.

All CVEs for youphptube

CVE-2021-25878 youphptube vulnerability CVSS: 4.3 01 Nov 2021, 12:15 UTC

AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

CVE-2021-25877 youphptube vulnerability CVSS: 9.0 01 Nov 2021, 12:15 UTC

AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.

CVE-2021-25876 youphptube vulnerability CVSS: 4.3 01 Nov 2021, 12:15 UTC

AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

CVE-2021-25875 youphptube vulnerability CVSS: 4.3 01 Nov 2021, 12:15 UTC

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the searchPhrase parameter which allows a remote attacker to steal administrators' session cookies or perform actions as an administrator.

CVE-2021-25874 youphptube vulnerability CVSS: 5.0 01 Nov 2021, 12:15 UTC

AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve databases information such as application passwords hashes.

CVE-2019-18662 youphptube vulnerability CVSS: 7.5 02 Nov 2019, 15:15 UTC

An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in getFromChat in plugin/LiveChat/Objects/LiveChatObj.php) before being used to construct a SQL query. This can be exploited by malicious users to, e.g., read sensitive data from the database through in-band SQL Injection attacks. Successful exploitation of this vulnerability requires the Live Chat plugin to be enabled.

CVE-2019-5151 youphptube vulnerability CVSS: 7.5 31 Oct 2019, 20:15 UTC

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2019-5150 youphptube vulnerability CVSS: 6.8 31 Oct 2019, 20:15 UTC

An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. When the "VideoTags" plugin is enabled, a specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of service, exfiltration of the database and local file inclusion, which could potentially further lead to code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2019-5129 youphptube vulnerability CVSS: 7.5 25 Oct 2019, 18:15 UTC

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getSpiritsFromVideo.php is vulnerable to a command injection attack.

CVE-2019-5128 youphptube vulnerability CVSS: 7.5 25 Oct 2019, 18:15 UTC

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImageMP4.php is vulnerable to a command injection attack.

CVE-2019-5127 youphptube vulnerability CVSS: 7.5 25 Oct 2019, 18:15 UTC

A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for providing encoder functionality in YouPHPTube. The parameter base64Url in /objects/getImage.php is vulnerable to a command injection attack.

CVE-2019-5123 youphptube vulnerability CVSS: 6.5 25 Oct 2019, 18:15 UTC

Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.

CVE-2019-5122 youphptube vulnerability CVSS: 6.5 25 Oct 2019, 18:15 UTC

SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter name in /objects/pluginSwitch.json.php.

CVE-2019-5121 youphptube vulnerability CVSS: 6.5 25 Oct 2019, 18:15 UTC

SQL injection vulnerabilities exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with Parameter uuid in /objects/pluginSwitch.json.php

CVE-2019-5120 youphptube vulnerability CVSS: 6.5 25 Oct 2019, 18:15 UTC

An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configurations, access the underlying operating system.

CVE-2019-5119 youphptube vulnerability CVSS: 6.5 25 Oct 2019, 18:15 UTC

An exploitable SQL injection vulnerability exist in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configurations, access the underlying operating system.

CVE-2019-5117 youphptube vulnerability CVSS: 6.5 25 Oct 2019, 18:15 UTC

Exploitable SQL injection vulnerabilities exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configuration, access the underlying operating system.

CVE-2019-5116 youphptube vulnerability CVSS: 6.5 25 Oct 2019, 18:15 UTC

An exploitable SQL injection vulnerability exists in the authenticated part of YouPHPTube 7.6. Specially crafted web requests can cause a SQL injection. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and in certain configuration, access the underlying operating system.

CVE-2019-5114 youphptube vulnerability CVSS: 9.3 25 Oct 2019, 18:15 UTC

An exploitable SQL injection vulnerability exists in the authenticated portion of YouPHPTube 7.6. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to trigger this vulnerability, potentially allowing exfiltration of the database, user credentials and,in certain configuration, access the underlying operating system.

CVE-2019-16124 youphptube vulnerability CVSS: 7.5 09 Sep 2019, 02:15 UTC

In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.

CVE-2019-14430 youphptube vulnerability CVSS: 5.0 20 Aug 2019, 14:15 UTC

plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.