CVE-2026-33723 is a SQL Injection vulnerability in WWBN AVideo versions up to and including 26.0, where the `Subscribe::save()` method improperly concatenates user-controlled input into an SQL query. This medium-severity flaw (CVSS 6.5) allows an authenticated attacker to execute arbitrary SQL commands over the network with low complexity. The primary impact is high confidentiality, enabling the extraction of sensitive data like password hashes and API keys. There is currently no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, indicating a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.