
CVE-2026-33025 AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_POST['sort'] array… https://www.cve.org/CVERecord?id=CVE-2026-33025
Post summary
The statement reveals a SQL injection vulnerability in AVideo versions before 8.0, impacting the getSqlFromPost method via the $_POST['sort'] array, with no evidence of exploits, patches, or false claims.
