CVE-2026-81732 PUBLISHED

WWBN AVideo through 30.0 Information Disclosure via report4.json.php

Assigner: VulnCheck
Reserved: 27.08.2026 Published: 28.08.2026 Updated: 28.08.2026

WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or authorization.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor WWBN
Product AVideo
Versions Default: unaffected
  • affected from 0 to 30.0 (incl.)

Credits

  • skeletonsec reporter

References

Problem Types

  • Exposure of Sensitive Information to an Unauthorized Actor CWE