Gray Hats@the_yellow_fallPatch
AVideo has released a patch for CVE‑2026‑28501 and CVE‑2026‑28502, which allow unauthenticated SQL injection and remote code execution; users are advised to update to version 23.
CRAC Learning - Tech@cracbotDisclosure
The post announces a critical SQL injection flaw (CVE-2026-28501) in WWBN AVideo prior to v24.0, citing a CVSS score and linking to the NVD entry, without mentioning exploitation, PoC, or remediation.
CVE@CVEnewDisclosure
An unauthenticated SQL injection vulnerability (CVE-2026-28501) in WWBN AVideo’s objects/videos.json.ph was disclosed for versions prior to 24.0, with no PoC, exploit, or patch details provided.
The Hacker Wire@TheHackerWireDisclosure
The post announces a critical unauthenticated SQL injection vulnerability in WWBN AVideo (pre‑v24.0), identifying affected files but providing no PoC, exploit code, patch, or evidence of active exploitation.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert references CVE-2026-28501, describing an unauthenticated SQL injection vulnerability in WWBN AVideo, but does not provide a PoC, exploit, or patch.
CVEFind.com@CveFindComPatch
The tweet warns of a critical unauthenticated SQL injection in AVideo and urges updating to v24.0 to fix it.