Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Youphptube

First CVE: Aug 20, 2019Active for: 7 yearsTotal CVEs: 23
62.4
VTI Score
TOP TARGET

Youphptube is a video hosting and streaming platform with a narrow product line centered on its core application and encoder utility, yet its vulnerabilities have achieved prominence in the landscape owing to their severity profile and public exploit availability. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the attack surface inherent to a web-facing media platform that processes user input across multiple contexts. The exposure recurs through a distinctive cluster of input-handling and injection weakness classes—SQL injection, cross-site scripting, OS command injection, code injection, and path traversal—that arise from insufficient sanitization across the application's request pipeline, authentication mechanisms, and file-serving components. These weakness classes are particularly dangerous in streaming platforms because they enable both data exfiltration and server compromise; defenders should treat Youphptube deployments as high-risk and prioritize patching and input-validation hardening. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Youphptube over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2019
6 years ago
Most Recent CVE
Jan 13, 2026
193 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5127CRITICAL
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exis
Oct 25, 20199.866NOYES
CVE-2019-5129CRITICAL
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exis
Oct 25, 20199.862NOYES
CVE-2019-5128CRITICAL
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exis
Oct 25, 20199.857NOYES
CVE-2019-16124CRITICAL
In YouPHPTube 7.4, the file install/checkConfiguration.php has no access control, which leads to everyone being able to edit the configuration file, and insert malicious PHP code.
Sep 9, 20199.843NONO
CVE-2019-18662CRITICAL
An issue was discovered in YouPHPTube through 7.7. User input passed through the live_stream_code POST parameter to /plugin/LiveChat/getChat.json.php is not properly sanitized (in
Nov 2, 20199.830NONO
CVE-2019-5151CRITICAL
An exploitable SQL injection vulnerability exist in YouPHPTube 7.7. A specially crafted unauthenticated HTTP request can cause a SQL injection, possibly leading to denial of servic
Oct 31, 20199.828NONO
CVE-2019-5123HIGH
Specially crafted web requests can cause SQL injections in YouPHPTube 7.6. An attacker can send a web request with Parameter dir in /objects/pluginSwitch.json.php.
Oct 25, 20198.827NONO
CVE-2019-14430MEDIUM
plugin/Audit/Objects/AuditTable.php in YouPHPTube through 7.2 allows SQL Injection.
Aug 20, 20195.327NOYES
CVE-2021-25877HIGH
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file sav
Nov 1, 20217.226NONO
CVE-2021-25874HIGH
AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior is affected by a SQL Injection SQL injection in the catName parameter which allows a remote unauthenticated attacker to retrieve
Nov 1, 20217.526NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
26%
43%
30%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.3%)
Network22 (95.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (95.7%)
High1 (4.3%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low9 (39.1%)
High1 (4.3%)
None13 (56.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
13.0% of CVEs· 97th percentile
ExploitDB
1 CVE
4.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Youphptube.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Youphptube — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Youphptube's Products

View all 3 CNAs →

Top CWEs