CVE-2026-33770
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fixCleanTitle() static method in objects/category.php constructs a SQL SELECT query by directly interpolating both $clean_title and $id into the query string without using prepared statements or parameterized queries. An attacker who can trigger category creation or renaming with a crafted title value can inject arbitrary SQL.
Commit 994cc2b3d802b819e07e6088338e8bf4e484aae4 contains a patch.
CRITICAL · CVSS 9.8
EPSS 0.00027
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0