WWBN AVideo <= 26.0 contains multiple vulnerabilities in the CloneSite plugin including unauthenticated exposure of clone secret keys and OS command injection in rsync command construction, letting unauthenticated attackers achieve remote code execution.
id: CVE-2026-33478
info:
name: AVideo <= 26.0 - WWBN AVideo - Remote Code Execution
author: pus
...