PT-2026-51173 · Avideo · Avideo

·

CVE-2026-56341

·

Published

2026-03-29

·

Updated

2026-06-20

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 26.1
Description Multiple payment plugins contain unauthenticated 'list.json.php' endpoints that lack proper authorization checks. This allows unauthenticated attackers to perform direct GET requests to these endpoints to retrieve sensitive payment transaction data, including PayPal tokens, Authorize.Net webhooks, Bitcoin transaction records, agreement IDs, user financial records, and API responses.
Recommendations Update to a version later than 26.0. As a temporary mitigation, restrict access to the 'list.json.php' endpoints within payment plugins.

Exploit

Fix

Missing Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56341
GHSA-RG7Q-4223-PHJW
GHSA-WPRJ-9CVC-5W37

Affected Products

Avideo