CVE-2026-33294Disclosure(wwbn / avideo)

LOWCVSS 4.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for wwbn avideo systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other URL-fetching endpoints in AVideo that were hardened with `isSSRFSafeURL()`, this code path was missed. An authenticated attacker can force the server to make HTTP requests to internal network resources and retrieve the responses by viewing the saved video thumbnail. Version 26.0 fixes the issue.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-23)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-22: 1Mentions · 2026-03-23: 2Active Exploitation · 2026-03-23: 1Technical Details · 2026-03-22: 103-2203-23
Signal classification3 categories
Disclosure
133.3%
Active Exploitation
133.3%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-232
Active Exploitation1General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-33294 WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thu… https://www.cve.org/CVERecord?id=CVE-2026-33294

    Post summary

    The text references CVE-2026-33294 with minimal detail and no evidence of exploitation, patch, or PoC, making it largely a generic mention.

    0000090
    56.8K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting WWBN AVideo (CVE-2026-33294) https://vuldb.com/?ctiid.352469

    Post summary

    The brief report indicates attackers are targeting CVE‑2026‑33294, suggesting active exploitation but lacking detailed evidence.

    0000061
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33294 Server-Side Request Forgery in WWBN AVideo BulkEmbed Plugin Before Version 26.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33294

    Post summary

    The text announces a Server‑Side Request Forgery vulnerability affecting the WWBN AVideo BulkEmbed Plugin prior to version 26.0, but provides no evidence of exploitation, PoC, or patch details.

    0000040
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more