CVE-2026-105086
published 2026-10-04CVE-2026-105086: WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting…
PriorityP339high8.7CVSS 3.1
AVNACLPRLUIRSCCHIHAN
EPSS
0.23%
12.5th percentile
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | 12.4 – 29.2.0 | — |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 29.2.0 safeString cross site scripting
vuldb·2026-10-04·CVSS 8.7
CVE-2026-105086 [HIGH] WWBN AVideo up to 29.2.0 safeString cross site scripting
A vulnerability classified as problematic has been found in WWBN AVideo up to 29.2.0. Affected by this issue is the function safeString. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-105086. The attack is possible to be carried out remotely. No exploit exists.
GHSA
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles.
ghsa_unreviewed·2026-10-04
CVE-2026-105086 [CRITICAL] CWE-79 WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles.
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/WWBN/AVideo/commit/c4b6ca95a0ae3efa09919a98879870086cff150ehttps://github.com/WWBN/AVideo/security/advisories/GHSA-q62w-927x-vhhfhttps://www.vulncheck.com/advisories/wwbn-avideo-12.4-through-29.2.0-stored-xss-via-double-encoded-video-titlehttps://github.com/WWBN/AVideo/security/advisories/GHSA-q62w-927x-vhhf
2026-10-04
Published