
CVE-2026-33024 AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpoints getImage.php… https://www.cve.org/CVERecord?id=CVE-2026-33024
Post summary
The post discloses that AVideo versions prior to 8.0 are vulnerable to a Server‑Side Request Forgery (CWE‑918) via the getImage.php endpoint, but does not provide a PoC, exploit, or mitigation.

