Youphptube is a video hosting and streaming platform with a narrow product line centered on its core application and encoder utility, yet its vulnerabilities have achieved prominence in the landscape owing to their severity profile and public exploit availability. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the attack surface inherent to a web-facing media platform that processes user input across multiple contexts. The exposure recurs through a distinctive cluster of input-handling and injection weakness classes—SQL injection, cross-site scripting, OS command injection, code injection, and path traversal—that arise from insufficient sanitization across the application's request pipeline, authentication mechanisms, and file-serving components. These weakness classes are particularly dangerous in streaming platforms because they enable both data exfiltration and server compromise; defenders should treat Youphptube deployments as high-risk and prioritize patching and input-validation hardening. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Youphptube over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5127CRITICAL A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exis | Oct 25, 2019 | 9.8 | 66 | NO | YES |
CVE-2019-5129CRITICAL A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exis | Oct 25, 2019 | 9.8 | 62 | NO | YES |
CVE-2019-5128CRITICAL A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exis | Oct 25, 2019 | 9.8 | 57 | NO | YES |
CVE-2019-16124CRITICAL In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code. | Sep 9, 2019 | 9.8 | 43 | NO | NO |
CVE-2019-18662CRITICAL An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in | Nov 2, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-5151CRITICAL An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of servic | Oct 31, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-5123HIGH Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php. | Oct 25, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-14430MEDIUM plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection. | Aug 20, 2019 | 5.3 | 27 | NO | YES |
CVE-2021-25877HIGH AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file sav | Nov 1, 2021 | 7.2 | 26 | NO | NO |
CVE-2021-25874HIGH AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve | Nov 1, 2021 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Youphptube.
Media articles that mention a CVE ID that affects a product developed by Youphptube — matched by CVE ID, not by vendor name.