YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 14 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 14 Jan 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Youphptube
Youphptube youphptube
Vendors & Products Youphptube
Youphptube youphptube

Tue, 13 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description YouPHPTube <= 7.8 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the redirectUri parameter in the signup page. Attackers can craft special signup URLs with embedded script tags to execute arbitrary JavaScript in victims' browsers when they access the signup page.
Title YouPHPTube <= 7.8 - Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-01-14T15:13:28.351Z

Reserved: 2026-01-10T13:48:08.268Z

Link: CVE-2021-47750

cve-icon Vulnrichment

Updated: 2026-01-14T15:13:25.906Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-13T23:15:49.097

Modified: 2026-01-14T16:25:12.057

Link: CVE-2021-47750

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-14T10:49:11Z

Weaknesses