
CVE-2026-40935 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from the query string wi… https://www.cve.org/CVERecord?id=CVE-2026-40935
Post summary
This post discloses CVE-2026-40935, detailing that AVideo’s getCaptcha.php accepts the CAPTCHA length parameter from the query string in affected versions.
