
CVE-2026-33238 WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob… https://www.cve.org/CVERecord?id=CVE-2026-33238
Post summary
The post announces CVE-2026‑33238, detailing how an unsanitized path parameter is accepted, but provides no exploit, patch, or evidence of active use.

