CVE-2026-92580

CVE-2026-92580 published: In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain s...

View full NVD advisory → ← Back to CVE watch