Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-89251

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Sep 11, 2026
Vendor unknown

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet balance for any campaign video without proof an ad actually played.

References