cvedb.io
CVE-2026-35449
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2026-04-06T22:16:23.310 · Last modified 2026-06-17T10:40:37.020

Summary

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addresses, session IDs, and user agents to unauthenticated visitors.

Affected products

wwbn — avideo

Does this affect you?

Add your gear to cvedb and we'll alert you only when wwbn ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.