Description
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
Published: 2026-10-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that allows authenticated uploaders to insert malicious code by submitting doubly‑encoded HTML entities in video titles. The application’s safeString() routine strips tags before decoding entities, and this process is executed twice—first during setTitle() and again during save()—allowing the payload to persist in the database and later be rendered on trending, gallery, embed, and playlist pages. If executed, the script runs in the context of any user viewing those pages, enabling defacement, cookie theft, or session hijacking.

Affected Systems

All releases of the WWBN AVideo web application from version 12.4 through 29.2.0 are impacted. Deployments within this version range that provide upload privileges to users are at risk, because any authenticated uploader can exploit the flaw. Administrators should confirm whether their instances include these versions and assess the scope of upload permissions.

Risk and Exploitability

With a CVSS score of 9.3, the flaw is classified as High severity. No EPSS score is available, and it is not listed in the CISA KEV catalog, but the absence of those metrics does not lessen the danger. The likely attack vector is stored XSS via double‑encoded video titles, requiring the attacker to possess valid uploader credentials or to compromise an account. Once injected, the payload can execute when any user visits the page that displays the title, giving attackers broad opportunities to execute arbitrary JavaScript in the victim’s browser.

Generated by OpenCVE AI on October 4, 2026 at 17:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the security fix by updating to a patched release of WWBN AVideo or by applying the commit that disables double‑encoded entity injection (https://github.com/WWBN/AVideo/commit/c4b6ca95a0ae3efa09919a98879870086cff150e).
  • Restrict upload permissions to trusted users only, ensuring that only accounts with verified intent can submit video titles. This reduces the number of accounts that could exploit the flaw.
  • Implement an input sanitization rule that rejects or cleans double‑encoded entities in video titles before they are stored, preventing malicious payloads from persisting in the database.

Generated by OpenCVE AI on October 4, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
Title WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T15:10:23.281Z

Reserved: 2026-10-03T01:31:40.183Z

Link: CVE-2026-105086

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T16:16:30.183

Modified: 2026-10-04T16:16:30.183

Link: CVE-2026-105086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T18:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')