Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php endpoint that execute when viewing extra info pages or profile forms that render the typeToHTML function.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting via unsanitized input
Action: Apply Patch
AI Analysis

Impact

A stored cross‑site scripting vulnerability exists in the CustomizeUser plugin of AVideo. The flaw is triggered when the field_name parameter is submitted to the add.json.php endpoint and the value is stored without sanitization. When the stored value is later rendered in extra info pages or profile forms through the typeToHTML function, the embedded script executes in the browser context of any user who views the affected page. This can lead to malicious content injection, session hijacking, or def input validation flaw, identified as CWE‑79.

Affected Systems

The affected product is AVideo from WWBN. All installations that run any version of AVideo with the default CustomizeUser plugin configuration are susceptible until the patch or mitigation is applied. No specific version boundary has been cited by the CNA.

Risk and Exploitability

The CVSS score of 9.3 indicates a high exploitable risk. The EPSS score is not currently available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting there is no confirmed exploitation in the wild yet. The primary attack surface is submitting a value to add.json.php; once stored, the malicious code is delivered to all users who view the edited profile access can inject arbitrary scripts that execute with the same privileges as the page viewer.

Generated by OpenCVE AI on September 11, 2026 at 14:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest AVideo release that includes input sanitization for the field_name parameter in the CustomizeUser plugin.
  • If a patch is not yet available, temporarily disable the CustomizeUser plugin or delete the vulnerable field_name entries via the admin interface to prevent stored malicious content.
  • Deploy a content security policy that blocks inline scripts and limits script sources to trusted domains, adding an extra layer of applied.

Generated by OpenCVE AI on September 11, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php endpoint that execute when viewing extra info pages or profile forms that render the typeToHTML function.
Title AVideo CustomizeUser Stored XSS via field_name Parameter
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T20:29:51.333Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89254

cve-icon Vulnrichment

Updated: 2026-09-11T17:43:25.319Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:55.690

Modified: 2026-09-11T21:17:57.507

Link: CVE-2026-89254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T19:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')