CVE-2026-33513
AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)
Summary
Affected Packages (1)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| wwbn/avideo | packagist | 10.4, 10.8, 11, 11.1 (+13 more) | Range-based data available |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-22Path TraversalMITRE
- CWE-98
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 8.6 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
References
Frequently Asked Questions
- What is CVE-2026-33513?
- AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP) This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.6/10).
- How do I check if my project is affected by CVE-2026-33513?
- CVE-2026-33513 affects wwbn/avideo. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-33513 and 200,000+ other known vulnerabilities.
Severity & Exploitability
High exploitability or significant impact. Prioritize remediation within days.
Also Known As
Related CVEs
- CVE-2023-25313CRITICAL
AVideo contains Command injection when embedding a video link
- CVE-2026-28501CRITICAL
AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects/videos.json.php
- CVE-2026-28502CRITICAL
AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction
- CVE-2023-49599CRITICAL
WWBN AVideo Insufficient Entropy vulnerbaility
- CVE-2026-33480HIGH
AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy
- CVE-2026-41064HIGH
WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection
- CVE-2026-33719HIGH
AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment
- CVE-2026-40925HIGH
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies