CVE-2026-92581: Wwbn Avideo
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.
Affected products
- Wwbn Avideo: up to and including 29.0
Published 2026-09-16. Last modified 2026-09-22.