
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33770 is a SQL Injection vulnerability in WWBN AVideo's category.php file, specifically within the fixCleanTitle() static method, which constructs SQL queries by directly interpolating user-supplied values without parameterization. It affects AVideo versions up to and including 26.0. The vulnerability was published on March 24, 2026, and added to the GitHub Advisory Database on March 26, 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.1 (High) (GitHub Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command). The vulnerable fixCleanTitle() method in objects/category.php directly interpolates both $clean_title (a user-supplied category name after slug conversion) and $id (the category ID) into a raw SQL string: SELECT * FROM categories WHERE clean_name = '{$clean_title}' with an optional AND id != {$id} clause — neither value is escaped or parameterized (GitHub Advisory). The slug conversion process strips spaces and some special characters but leaves SQL metacharacters (e.g., single quotes) intact, allowing UNION-based injection payloads to survive into the query. Exploitation requires triggering category creation or renaming with a crafted title, which is nominally an admin-level action, though lower-privilege paths may exist depending on plugin configuration. A proof-of-concept payload is publicly documented in the security advisory (AVideo Advisory).
Successful exploitation enables full database read access via UNION-based SQL injection, exposing user credentials (usernames and password hashes), private video metadata, and user personally identifiable information (PII). An attacker who exfiltrates database credentials could potentially escalate access to the underlying database server or pivot to other systems sharing those credentials. The confidentiality impact is high, while integrity and availability of the vulnerable system are not directly affected by this specific injection vector (GitHub Advisory).
A proof-of-concept exploit is publicly available in the GitHub security advisory, providing a concrete UNION injection payload and step-by-step reproduction instructions (AVideo Advisory). Feedly classifies the exploit confidence as high and notes it is a real exploit targeting external AVideo deployments. There is no current evidence of in-the-wild exploitation, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.047%, indicating a low but non-negligible probability of exploitation in the near term (GitHub Advisory).
test' UNION SELECT username,password,3,4,5,6,7,8,9,10 FROM users-- -fixCleanTitle() method in objects/category.php to process the input.SELECT * FROM categories WHERE clean_name = 'test' UNION SELECT username,password,3,4,5,6,7,8,9,10 FROM users-- -' LIMIT 1, returning rows from the users table.'), UNION SELECT, --, or FROM users in category title parameters.UNION SELECT username,password or queries referencing the users table from the category management context./objects/category.php or related admin save endpoints) with encoded or raw SQL injection strings in the body (AVideo Advisory).The fix is available in commit 994cc2b3d802b819e07e6088338e8bf4e484aae4, which refactors fixCleanTitle() to use prepared statements with ? placeholders and bound parameters ($clean_title as a string and intval($id) as an integer) (Patch Commit). Administrators should update AVideo to a version incorporating this commit (patched versions >= 26.0 per the advisory) immediately. As a temporary workaround, restrict access to the category management interface to trusted IP addresses via web server configuration, and deploy WAF rules to detect and block SQL injection patterns in request parameters (GitHub Advisory).
The vulnerability was reported by security researcher athuljayaram and published by AVideo maintainer DanielnetoDotCom on March 24, 2026, with a patch committed the same day (AVideo Advisory). The CVE received automated coverage from vulnerability aggregators including VulDB, CVEFeed, and CIRCL, but no notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE notification channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."