CVE-2026-28501Disclosure(wwbn / avideo)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.php components. The application fails to properly sanitize the catName parameter when it is supplied via a JSON-formatted POST request body. Because JSON input is parsed and merged into $_REQUEST after global security checks are executed, the payload bypasses the existing sanitization mechanisms. This issue has been patched in version 24.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-06); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-04: 1Mentions · 2026-03-06: 4Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-06: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-06: 4Technical Details · 2026-03-11: 103-0403-0603-11
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-041
Patch1
2026-03-064
Disclosure3Patch1
2026-03-111
Disclosure1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    AVideo patches two critical flaws (CVE-2026-28501 & 28502) allowing unauthenticated SQL injection and remote code execution. Update to version 23 now. #AVideo #CyberSecurity #SQLInjection #RCE #CVE #InfoSec #Vulnerability #OpenSource #ThreatIntel https://securityonline.info/critical-vulnerabilities-in-avideo-from-sql-injection-to-remote-code-execution/

    Post summary

    AVideo has released a patch for CVE‑2026‑28501 and CVE‑2026‑28502, which allow unauthenticated SQL injection and remote code execution; users are advised to update to version 23.

    00030219
    10.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28501 (CVSS:9.8, CRITICAL) is Undergoing Analysis. WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exis..https://nvd.nist.gov/vuln/detail/CVE-2026-28501 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces a critical SQL injection flaw (CVE-2026-28501) in WWBN AVideo prior to v24.0, citing a CVSS score and linking to the NVD entry, without mentioning exploitation, PoC, or remediation.

    0000027
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28501 WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.ph… https://www.cve.org/CVERecord?id=CVE-2026-28501

    Post summary

    An unauthenticated SQL injection vulnerability (CVE-2026-28501) in WWBN AVideo’s objects/videos.json.ph was disclosed for versions prior to 24.0, with no PoC, exploit, or patch details provided.

    00000121
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28501 - Critical WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objects/videos.json.php and objects/video.p... https://www.thehackerwire.com/vulnerability/CVE-2026-28501/ https://t.co/wdEZMdfm1M

    Post summary

    The post announces a critical unauthenticated SQL injection vulnerability in WWBN AVideo (pre‑v24.0), identifying affected files but providing no PoC, exploit code, patch, or evidence of active exploitation.

    0000044
    125 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28501 - WWBN AVideo: Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php Intel Report: https://ift.tt/IEtHPZQ

    Post summary

    The alert references CVE-2026-28501, describing an unauthenticated SQL injection vulnerability in WWBN AVideo, but does not provide a PoC, exploit, or patch.

    0000042
    343 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-28501: CRITICAL] Warning: Unauthenticated SQL Injection flaw discovered in AVideo platform pre-version 24.0. Ensure updates to version 24.0 are applied to patch this vulnerability. #cybersecurity#cve,CVE-2026-28501,#cybersecurity https://cvefind.com/CVE-2026-28501

    Post summary

    The tweet warns of a critical unauthenticated SQL injection in AVideo and urges updating to v24.0 to fix it.

    0000080
    597 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more