
CVE-2026-33351 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33351
Post summary
The post merely lists the CVE ID and its NIST CVSS score, offering no further details or actionable information.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended configuration for this file), the `$_REQUEST['webSiteRootURL']` parameter is used directly to construct a URL that is fetched server-side via `file_get_contents()`. No authentication, origin validation, or URL allowlisting is performed. Version 26.0 contains a patch for the issue.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-20 | 1 | Disclosure1 |
| 2026-03-23 | 3 | Disclosure2Patch1 |
| 2026-04-07 | 1 | General1 |

CVE-2026-33351 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33351
Post summary
The post merely lists the CVE ID and its NIST CVSS score, offering no further details or actionable information.

CVE-2026-33351 Server-Side Request Forgery in WWBN AVideo Live Plugin Before Version 26.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33351
Post summary
CVE-2026-33351 is a Server‑Side Request Forgery vulnerability affecting WWBN AVideo Live Plugin versions older than 26.0.

[CVE-2026-33351: CRITICAL] AVideo discovered and fixed a Server-Side Request Forgery (SSRF) vulnerability in their Live plugin prior to version 26.0, enhancing cyber security.#cve,CVE-2026-33351,#cybersecurity https://cvefind.com/CVE-2026-33351
Post summary
AVideo announced a critical SSRF flaw in its Live plugin and released a fix before version 26.0, but no proof of concept or active exploitation details were provided.

🔴 CVE-2026-33351 - Critical WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the ... https://www.thehackerwire.com/vulnerability/CVE-2026-33351/ https://t.co/JVZcxsKxhv
Post summary
CVE-2026-33351 is a critical SSRF vulnerability in WWBN AVideo prior to version 26.0 affecting the plugin/Live/standAloneFiles/saveDVR.json.php file; the post does not provide a PoC, exploit code, active exploitation evidence, or patch information.

An unauthenticated SSRF vulnerability (CVE-2026-33351) in `AVideo` allows for a verification bypass. Review `AVideo` deployments for exposure. #SSRF #AVideo #infosec https://www.pulsepatch.io/posts/cve-2026-33351-avideo-unauthenticated-ssrf-verification-bypass
Post summary
The tweet announces a new unauthenticated SSRF flaw (CVE‑2026‑33351) in AVideo capable of bypassing verification, urging users to review deployments for exposure.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | wwbn | avideo | - | - | - |