CVE-2026-33025 is a high-severity SQL Injection vulnerability present in AVideo versions prior to 8.0, specifically in the getSqlFromPost() method where $_POST['sort'] array keys are directly used as SQL column identifiers. With a CVSS score of 8.8, this flaw allows a low-privileged attacker to achieve high impact on confidentiality, integrity, and availability over the network with low attack complexity and no user interaction. There is currently no evidence of active exploitation or public exploit code, and community discussion is minimal. The vulnerability is fixed in AVideo version 8.0, with WAF rules or access restrictions serving as potential workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo-encoder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.