CVE-2026-33507Disclosure(wwbn / avideo)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting `session.cookie_samesite = 'None'` for HTTPS connections, an unauthenticated attacker can craft a page that, when visited by an authenticated admin, silently uploads a malicious plugin containing a PHP webshell, achieving Remote Code Execution on the server. Commit d1bc1695edd9ad4468a48cea0df6cd943a2635f3 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 303-23
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33507 WWBN AVideo Remote Code Execution via Unauthenticated Plugin Upload Vuln... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33507 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The post announces the discovery of CVE-2026-33507, a remote code execution vulnerability in WWBN AVideo related to unauthenticated plugin uploads, with links to details but no PoC, exploit, or patch information provided.

    0000047
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33507: HIGH] Warning: Vulnerability in WWBN AVideo up to v26.0 allows unauthenticated attackers to upload malicious plugins, leading to remote code execution. Apply patch 'd1bc1695edd9ad4468a48cea0...#cve,CVE-2026-33507,#cybersecurity https://cvefind.com/CVE-2026-33507

    Post summary

    CVE-2026-33507 permits unauthenticated remote code execution via malicious plugin uploads in WWBN AVideo v26.0, and a vendor patch is available.

    0000038
    606 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33507 - High WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files cont... https://www.thehackerwire.com/vulnerability/CVE-2026-33507/ https://t.co/FK3x7hVEK4

    Post summary

    The tweet announces a high‑severity vulnerability in WWBN AVideo (CVE-2026-33507) affecting the plugin import endpoint, which lets administrators upload and install plugin ZIP files, potentially leading to unauthorized code execution.

    0000037
    144 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more