Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40929

20
FAUCET Score

OVERVIEW: CVE-2026-40929 is a cross-site request forgery (CSRF) vulnerability in WWBN AVideo version 29.0 and prior. The vulnerability exists in the commentDelete.json.php endpoint, which performs state-mutating operations without implementing standard CSRF protections such as token validation or origin/referrer checks. Because AVideo deliberately disables SameSite cookie restrictions to support cross-origin embedded players, authenticated users automatically transmit valid session credentials to attacker-controlled pages. SEVERITY: The vulnerability requires user interaction (a victim must visit an attacker's page) but has low attack complexity and requires no privileges to exploit. The attack vector is network-based. Authenticated users with comment deletion authority, including site moderators, video owners, and comment authors, can be manipulated into deleting comments in bulk. The CVSS score of 5.4 (MEDIUM) reflects limited integrity and availability impact with no confidentiality compromise. The EPSS score of 0.00015 indicates this CVE ranks lower than 99.97 percent of known vulnerabilities in terms of exploitation likelihood. EXPLOITATION STATUS: There is no indication of active exploitation in the wild. The vulnerability is not present on the Known Exploited Vulnerabilities (KEV) catalog and does not appear on any active exploit hot lists. No public exploit code has been reported. A fix is available in commit 184f36b1896f3364f864f17c1acca3dd8df3af27. Organizations using AVideo version 29.0 or earlier should prioritize updating to patched versions.

Impacted Technologies

VendorProductVersion(s)CPE
<= 29.0CPE matchmatch criteria
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 1st percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-8qm8-g55h-xmqrmedium

WWBN AVideo is missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators

Apr 14, 2026

References

github.com / WWBN/AVideo/commit/184f36b1896f3364f864f17c1acca3dd8df3af27
Patch
github.com / WWBN/AVideo/security/advisories/GHSA-8qm8-g55h-xmqr
ExploitMitigationVendor Advisory