A vulnerability classified as critical was found in WWBN AVideo up to 29.0. Affected by this issue is the function listFFmpegProcesses of the file plugin/API/standAlone/functions.php of the component FFmpeg Process Handler. The manipulation results in os command injection.

This vulnerability is reported as CVE-2026-63304. The attack can be launched remotely. No exploit exists.