CVE-2026-28501 | WWBN AVideo up to 23.x POST Request objects/videos.json.php sql injection (GHSA-pv87-r9qf-x56p)
A vulnerability, which was classified as critical, has been found in WWBN AVideo up to 23.x. The impacted element is an unknown function of the file objects/videos.json.php of the component POST Request Handler. The manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-28501. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.