
CVE-2026-33761 WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any authentication ch… https://www.cve.org/CVERecord?id=CVE-2026-33761
Post summary
The CVE-2026-33761 disclosure reveals unauthenticated access to three `list.json.php` endpoints in the AVideo Scheduler plugin (up to version 26.0). No PoC, exploit, or patch information is included.
