A AegiFlow
MEDIUMCVSS 5.0

CVE-2026-19075

CVE-2026-19075 updated by NVD

Modified
2026-08-13
Sources
nvd

Summary

All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl= ` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back to the requester.

References

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.