
CVE-2026-40909 WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by directly concatenatin… https://www.cve.org/CVERecord?id=CVE-2026-40909
Post summary
The post references CVE-2026-40909, noting that in AVideo 29.0 and earlier the locale save endpoint constructs a file path via direct concatenation, which represents a potential path manipulation vulnerability.

