OVERVIEW: CVE-2026-40929 is a cross-site request forgery (CSRF) vulnerability in WWBN AVideo version 29.0 and prior. The vulnerability exists in the commentDelete.json.php endpoint, which performs state-mutating operations without implementing standard CSRF protections such as token validation or origin/referrer checks. Because AVideo deliberately disables SameSite cookie restrictions to support cross-origin embedded players, authenticated users automatically transmit valid session credentials to attacker-controlled pages. SEVERITY: The vulnerability requires user interaction (a victim must visit an attacker's page) but has low attack complexity and requires no privileges to exploit. The attack vector is network-based. Authenticated users with comment deletion authority, including site moderators, video owners, and comment authors, can be manipulated into deleting comments in bulk. The CVSS score of 5.4 (MEDIUM) reflects limited integrity and availability impact with no confidentiality compromise. The EPSS score of 0.00015 indicates this CVE ranks lower than 99.97 percent of known vulnerabilities in terms of exploitation likelihood. EXPLOITATION STATUS: There is no indication of active exploitation in the wild. The vulnerability is not present on the Known Exploited Vulnerabilities (KEV) catalog and does not appear on any active exploit hot lists. No public exploit code has been reported. A fix is available in commit 184f36b1896f3364f864f17c1acca3dd8df3af27. Organizations using AVideo version 29.0 or earlier should prioritize updating to patched versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 29.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.