CVE-2026-85162
AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to overwrite authenticated streamers' RTMP keys, passwords, and titles, hijacking live broadcasts.
- Published Sep 3, 2026
- CVSS 7.1 high
- 0.2% chance of exploitation in the next 30 days (EPSS)