HIGH 7.1 NVD
CVE-2026-89251
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-cwrf-q9jv-44px
- https://www.vulncheck.com/advisories/avideo-missing-authorization-via-ad-server-log-php-wa
- https://github.com/WWBN/AVideo/security/advisories/GHSA-cwrf-q9jv-44px
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-11 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.