
CVE-2026-39366 WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allow… https://www.cve.org/CVERecord?id=CVE-2026-39366
Post summary
The text announces a flaw in AVideo’s PayPal IPN handler (CVE‑2026‑39366) where missing transaction deduplication allows duplicate payments in versions 26.0 and earlier.
