All verified exploits

CVE-2026-33770 Authenticated SQL Injection in AVideo Category Management

Pentest high AVideo Added cve-pentest-cve-2026-33770

Detects AVideo installations at version 26.0 or earlier. The fixCleanTitle() static method in objects/category.php constructs a SQL SELECT query by directly interpolating $clean_title and $id without parameterized queries. An authenticated user with category-creation privileges can inject arbitrary SQL to extract database contents including admin credentials and user PII via UNION injection. Update AVideo to a version after commit 994cc2b.

Is your app exploitable through CVE-2026-33770?

Scan your domain free