CVE-2026-43885: Wwbn Avideo
High severity, CVSS 7.7. EPSS: 0.4% chance of exploitation in the next 30 days.
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b contains an updated fix.
Affected products
- Wwbn Avideo: up to and including 29.0
Published 2026-05-11. Last modified 2026-06-17.