logo

Critical Vulnerabilities in AVideo: From SQL Injection to Remote Code Execution

ID: 7153379e-3115-5bb4-a30c-95dfad369267

STIX ID: report--7153379e-3115-5bb4-a30c-95dfad369267

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive Summary:** Security researchers disclosed two high-severity vulnerabilities in the AVideo open-source streaming platform: CVE-2026-28501 (unauthenticated SQL injection, CVSS 9.8) that can enable database exfiltration and credential theft, and CVE-2026-28502 (authenticated plugin upload RCE) that permits full system compromise via malicious ZIP uploads; users are urged to upgrade to AVideo v23+ or apply mitigations such as disabling plugin imports and hardening web server execution permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.