Cross-Site Request Forgery in AVideo by WWBN
CVE-2026-83595

7.2HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-83595?

AVideo has a cross-site request forgery vulnerability located in the plugin/API/set.json.php file. This flaw enables attackers to exploit it by crafting malicious GET requests that bypass existing CSRF protections. By directing a victim's browser to a harmful URL containing specific API parameters, attackers gain the ability to perform state-altering actions such as deleting videos, deactivating user accounts, or altering playlists without any user interaction. This vulnerability underscores the importance of robust CSRF protection mechanisms in web applications.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.