CVE-2026-89251
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.15%
- CWE
- CWE-345
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- WWBN AVideo
Weakness type
Related vulnerabilities
- CVE-2026-44523 — Note Mark: JWT Secret Weakness allows Full Account Takeover via token forgery
- CVE-2026-48781 — Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-28185 — WordPress Log in with Google plugin <= 1.4.2 - Broken Authentication vulnerability
- CVE-2026-53513 — Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration
- CVE-2026-33471 — nimiq-block has skip block quorum bypass via out-of-range BitSet indices & u16 truncation
- CVE-2026-45058 — electerm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmark
- CVE-2026-44592 — Gradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoning