High severity8.1NVD Advisory· Published Sep 1, 2026
CVE-2026-83595
CVE-2026-83595
Description
AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to delete videos, deactivate accounts, or modify playlists without user interaction.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.