CVE-2026-50183
published 2026-07-15CVE-2026-50183: WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin…
PriorityP422medium4.7CVSS 3.1
AVNACHPRNUIRSCCLILAN
EPSS
0.16%
5.9th percentile
WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data API into the homepage gallery markup with no HTML encoding. The title is set by the YouTube video uploader (anyone in the world) and is treated by AVideo as trusted content. A YouTube uploader who controls a video matching the operator's configured query injects HTML into the AVideo homepage by setting their video's title to a JavaScript-bearing string; the payload then executes in the browser of every visitor who loads any page that renders the gallery. When the visitor is an AVideo administrator, the injected JavaScript performs any admin action (create user, promote to admin, change configuration, install plugin) that uses cookie-based authentication without an additional CSRF token, escalating the bug into full administrative takeover. The payload persists for the duration of cacheTimeout (default 3600 seconds) after the malicious title is set on YouTube and survives YouTube removing the hostile video for the same window. This issue has been addressed by commit https://github.com/WWBN/AVideo/commit/7292129eaee5f609beae103b5cb387d55f17b877.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wwbn | avideo | <= 29.0 | — |
| wwbn | avideo | 0 – 29.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WWBN AVideo up to 29.0 YouTubeAPI Plugin snippet.title render cross site scripting
vuldb·2026-07-15·CVSS 4.7
CVE-2026-50183 [MEDIUM] WWBN AVideo up to 29.0 YouTubeAPI Plugin snippet.title render cross site scripting
A vulnerability classified as problematic has been found in WWBN AVideo up to 29.0. This issue affects the function render of the file snippet.title of the component YouTubeAPI Plugin. The manipulation of the argument snippet.title leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-50183. The attack is possible to be carried out remotely. No exploit exists.
GHSA
WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
ghsa·2026-06-04
CVE-2026-50183 [MEDIUM] CWE-79 WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
# Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section
## Summary
A stored Cross-Site Scripting vulnerability (CWE-79; chained CWE-829, Inclusion of Functionality from Untrusted Control Sphere) in the AVideo YouTubeAPI plugin renders the `snippet.title` field returned by the YouTube Data API into the homepage gallery markup with no HTML encoding. The title is set by the YouTube video uploader (anyone in the world) and is treated by AVideo as trusted content. A YouTube uploader who controls a video matching the operator's configured query injects HTML into the AVideo homepage by setting their video's title to a JavaScript-bearing string; the payload then executes in the
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-15
Published