CVE-2026-92581

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily negative, with the corruption persisting in the denormalized counter until manual repair.

  • Published Sep 16, 2026
  • CVSS 5.3 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-92581 at the National Vulnerability Database