AVideo Vulnerability Allows Attackers to Manipulate Video Like Counts
CVE-2026-92581
5.3MEDIUM
What is CVE-2026-92581?
AVideo versions up to 29.0 exhibit a vulnerability in the Like::__construct() function, where it processes raw request parameters without proper validation. This flaw allows authenticated users to submit array-typed like parameters, enabling them to manipulate video like counts negatively. The resulting desynchronization between actual votes and counters can persist until manually corrected, creating a potential avenue for abuse and undermining the integrity of the voting system.
Affected Version(s)
AVideo 0 <= 29.0
