CVE Watchtower


← Back to CVE List

CVE-2026-45620NVD

Description

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) and hard-coded rowCount=10. This enables unauthenticated user enumeration.
Severity Level
MEDIUM (5.3)
Published Date
29/05/2026
Last Modified
01/06/2026
Exploitation Status
????