Detects AVideo installations at version 26.0 or earlier. The fixCleanTitle() static method in objects/category.php constructs a SQL SELECT query by directly interpolating $clean_title and $id without parameterized queries. An authenticated user with category-creation privileges can inject arbitrary SQL to extract database contents including admin credentials and user PII via UNION injection. Update AVideo to a version after commit 994cc2b.
Is your app exploitable through CVE-2026-33770?
Scan your domain free