CVE-2026-28501 is a critical unauthenticated SQL Injection vulnerability affecting WWBN AVideo prior to version 24.0. Specifically, the 'catName' parameter in 'objects/videos.json.php' and 'objects/video.php' is not properly sanitized when supplied via a JSON POST request, bypassing existing security checks. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a network-exploitable flaw with low attack complexity, requiring no privileges or user interaction, and leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No), no public exploit code (Metasploit, Nuclei, ExploitDB: None), and limited community discussion, the high severity warrants immediate patching to version 24.0.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 24.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.