Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40928

20
FAUCET Score

OVERVIEW CVE-2026-40928 is a Cross-Site Request Forgery (CSRF) vulnerability affecting WWBN AVideo versions 29.0 and prior. Multiple JSON endpoints under the objects directory lack anti-CSRF protections and accept state-changing requests via GET parameters or REQUEST data, allowing attackers to perform unauthorized actions on behalf of authenticated users without their knowledge. SEVERITY The vulnerability carries a CVSS score of 5.4 (Medium) with a network-based attack vector requiring minimal complexity and user interaction. An attacker can exploit this by tricking a logged-in victim into visiting a malicious webpage containing simple HTML elements like image tags or forms. The impact includes the ability to manipulate user likes/dislikes on comments, post comments authored by the victim with attacker-controlled text, and delete assets from categories if the victim has administrative rights. While the integrity and availability impacts are limited in scope, the unauthorized actions persist under the victim's identity. EXPLOITATION STATUS There is no indication of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and maintains an inactive status on threat tracking lists. The EPSS score of 0.00015 indicates this vulnerability ranks lower than 99.97 percent of all published CVEs in terms of exploitation likelihood. A fix is available in commit 7aaad601bd9cd7b993ba0ee1b1bea6c32ee7b77c, and organizations running affected versions should apply patches to eliminate the CSRF attack surface.

Impacted Technologies

VendorProductVersion(s)CPE
<= 29.0CPE matchmatch criteria
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 1st percentile among its peer group of 26,234 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-x2pw-9c38-cp2jmedium

WWBN AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion

Apr 14, 2026

References

github.com / WWBN/AVideo/commit/7aaad601bd9cd7b993ba0ee1b1bea6c32ee7b77c
Patch
github.com / WWBN/AVideo/security/advisories/GHSA-x2pw-9c38-cp2j
ExploitMitigationVendor Advisory