MEDIUMCVSS 5.0
CVE-2026-19075
CVE-2026-19075 updated by NVD
Summary
All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl= ` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.
References
Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.