CVE-2026-33767 | WWBN AVideo up to 26.0 Query String objects/like.php getLike videos_id sql injection (GHSA-fj74-qxj7-r3vc)
A vulnerability labeled as critical has been found in WWBN AVideo up to 26.0. This vulnerability affects the function getLike of the file objects/like.php of the component Query String Handler. Such manipulation of the argument videos_id leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-33767. The attack can be launched remotely. No exploit exists.
It is advisable to implement a patch to correct this issue.