CVE-2026-33770 is a critical SQL Injection vulnerability (CWE-89) affecting WWBN AVideo versions up to and including 26.0, specifically in the `fixCleanTitle()` method. This flaw allows an unauthenticated attacker to inject arbitrary SQL commands by crafting a malicious category title during creation or renaming. With a CVSS score of 9.8 (Critical), it presents a high risk, enabling full compromise of confidentiality, integrity, and availability with low attack complexity. While no active exploitation or public exploits are currently reported, and its EPSS score is very low, a patch is available in commit 994cc2b3d802b819e07e6088338e8bf4e484aae4.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.