CVE-2026-19075: Unknown All-In-One Video Gallery

Medium severity, CVSS 5.0. EPSS: 0.3% chance of exploitation in the next 30 days.

All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.

Affected products

  • Unknown All-In-One Video Gallery: before 4.9.2 (fixed in 4.9.2)

Published 2026-08-10. Last modified 2026-08-26.