Loading the current evidence view. Navigation and account controls remain available.
Indicator investigation
Loading the current evidence view. Navigation and account controls remain available.
Loading verdict, provenance, relationships and sightings.
Indicator
Type cve · source NVD CVE
Grouped attempts with latest status; expand for attempt history.
14 attempts · first 2026-09-02T00:06:25.423513Z · last 2026-09-05T18:32:18.634101Z
Not listed in CISA KEV (local)
Types: cisa_kev
14 attempts · first 2026-09-02T00:06:25.426688Z · last 2026-09-05T18:32:18.637148Z
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes. · CWEs: CWE-346
Types: nvd_local
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
Full investigation canvas with neighbor expansion.