Description
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
Published: 2026-10-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

WWBN AVideo up to version 29.2.0 has a stored cross‑site scripting flaw that lets an upload‑enabled user set a malicious trailer1 URL. The data is rendered unescaped in the YouPHPFlix2 templates and channel playlists, allowing attackers to break out of JavaScript context such as onclick attributes or iframe src parameters and run arbitrary code in the browsers of any viewer. This could be used to steal session cookies, deface pages, or launch phishing attacks against users who view the compromised video.

Affected Systems

Vendors: WWBN AVideo. Products: the AVideo platform, specifically version 29.2.0 and earlier where the trailer1 injection is present. Attack can affect any instance of this software running those versions.

Risk and Exploitability

With a CVSS score of 9.3 the vulnerability is considered critical. The exploit requires only that the attacker has upload rights on the affected instance, which is common in many installations. Because the issue is stored, the malicious payload is delivered to all viewers until removed, meaning a single compromised upload can continue to affect users indefinitely. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity recommends immediate remediation.

Generated by OpenCVE AI on October 4, 2026 at 17:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the AVideo installation to version 29.2.1 or later, where the trailer1 URL is properly sanitized.
  • Limit upload permissions to trusted administrators or implement a review process for user‑submitted URLs before they appear in public videos.
  • Implement input validation to escape or remove embedded script tags from trailer1 URLs, and consider a content‑security‑policy header to mitigate accidental execution of remaining payloads.

Generated by OpenCVE AI on October 4, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
Title WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-04T15:04:53.050Z

Reserved: 2026-10-03T01:44:56.582Z

Link: CVE-2026-105089

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T16:16:30.330

Modified: 2026-10-04T16:16:30.330

Link: CVE-2026-105089

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T17:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')