
CVE-2026-41056 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in `objects/functions.php` reflects any arbitrary… https://www.cve.org/CVERecord?id=CVE-2026-41056
Post summary
CVE‑2026‑41056 affects AVideo versions 29.0 and below by allowing arbitrary reflection in the allowOrigin function; no PoC, exploit, patch, or active exploitation is mentioned.

