CVE-2026-33351Disclosure(wwbn / avideo)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live plugin is deployed in standalone mode (the intended configuration for this file), the `$_REQUEST['webSiteRootURL']` parameter is used directly to construct a URL that is fetched server-side via `file_get_contents()`. No authentication, origin validation, or URL allowlisting is performed. Version 26.0 contains a patch for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-23); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-20: 1Mentions · 2026-03-23: 3Mentions · 2026-04-07: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-23: 3Technical Details · 2026-04-07: 103-2003-2304-07
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-201
Disclosure1
2026-03-233
Disclosure2Patch1
2026-04-071
General1
Full discourse5 posts
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-33351 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33351

    Post summary

    The post merely lists the CVE ID and its NIST CVSS score, offering no further details or actionable information.

    1000018
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33351 Server-Side Request Forgery in WWBN AVideo Live Plugin Before Version 26.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33351

    Post summary

    CVE-2026-33351 is a Server‑Side Request Forgery vulnerability affecting WWBN AVideo Live Plugin versions older than 26.0.

    0000028
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33351: CRITICAL] AVideo discovered and fixed a Server-Side Request Forgery (SSRF) vulnerability in their Live plugin prior to version 26.0, enhancing cyber security.#cve,CVE-2026-33351,#cybersecurity https://cvefind.com/CVE-2026-33351

    Post summary

    AVideo announced a critical SSRF flaw in its Live plugin and released a fix before version 26.0, but no proof of concept or active exploitation details were provided.

    0000033
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33351 - Critical WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the ... https://www.thehackerwire.com/vulnerability/CVE-2026-33351/ https://t.co/JVZcxsKxhv

    Post summary

    CVE-2026-33351 is a critical SSRF vulnerability in WWBN AVideo prior to version 26.0 affecting the plugin/Live/standAloneFiles/saveDVR.json.php file; the post does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    0000036
    144 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An unauthenticated SSRF vulnerability (CVE-2026-33351) in `AVideo` allows for a verification bypass. Review `AVideo` deployments for exposure. #SSRF #AVideo #infosec https://www.pulsepatch.io/posts/cve-2026-33351-avideo-unauthenticated-ssrf-verification-bypass

    Post summary

    The tweet announces a new unauthenticated SSRF flaw (CVE‑2026‑33351) in AVideo capable of bypassing verification, urging users to review deployments for exposure.

    0000040
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more