CVE-2026-105089
published 2026-10-04CVE-2026-105089: WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a…
PriorityP339high8.7CVSS 3.1
AVNACLPRLUIRSCCHIHAN
EPSS
0.23%
12.5th percentile
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 29.2.0 | — |
CVSS provenance
nvdv3.18.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL.
ghsa_unreviewed·2026-10-04
CVE-2026-105089 [CRITICAL] CWE-79 WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL.
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
VulDB
WWBN AVideo up to 29.2.0 cross site scripting
vuldb·2026-10-04·CVSS 8.7
CVE-2026-105089 [HIGH] WWBN AVideo up to 29.2.0 cross site scripting
A vulnerability described as problematic has been identified in WWBN AVideo up to 29.2.0. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-105089. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/WWBN/AVideo/commit/c4adfde13d1f18e3a415722471efdcd8ab480035https://github.com/WWBN/AVideo/security/advisories/GHSA-6wfr-c7fw-4xvwhttps://www.vulncheck.com/advisories/wwbn-avideo-through-29.2.0-stored-xss-via-trailer1-in-youphpflix2-templateshttps://github.com/WWBN/AVideo/security/advisories/GHSA-6wfr-c7fw-4xvw
2026-10-04
Published