CVE-2026-84480: Wwbn Avideo

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.

Affected products

  • Wwbn Avideo: up to and including 29.0

Published 2026-09-01. Last modified 2026-09-08.