Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every visitor of that video executes the payload in the AVideo origin.
Published: 2026-09-11
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Patch Immediately
AI Analysis

Impact

A stored cross‑site scripting flaw exists in the Bookmark plugin of AVideo. Chapter names entered by a video owner are inserted directly into the watch‑page HTML without HTML encoding or sanitization. Because the payload executes in the context of the site’s origin, any script injected into a bookmark name runs in the browser of every user who views the affected video. This can lead to session hijacking, credential theft, or the execution of arbitrary client‑side code.

Affected Systems

The vulnerability affects AVideo from WWBN, specifically the state of the repository at commit c3edcc274c389816d434acadac07ee78eaf330c1. No specific product version numbers are listed, so any deployment of AVideo that contains this commit is susceptible until patched.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity, but the EPSS score is not provided. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits are documented. The attack requires an authenticated video owner who can create or edit bookmark entries; once a malicious bookmark name is stored, any visitor to the video will execute the injected script. This stored‑XSS makes the exploit widely available to any user of the affected video, providing a broad surface for client‑side attacks.

Generated by OpenCVE AI on September 11, 2026 at 14:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch or upgrade to the latest AVideo release that fixes the missing HTML encoding in the Bookmark plugin.
  • Delete or sanitize all existing bookmark entries that contain user‑supplied characters before rendering them.
  • Implement input validation and encoding for all user‑controlled data to prevent future injection of executable markup.

Generated by OpenCVE AI on September 11, 2026 at 14:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every visitor of that video executes the payload in the AVideo origin.
Title AVideo Bookmark Plugin Stored XSS via Chapter Names
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-79
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T19:16:41.765Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89256

cve-icon Vulnrichment

Updated: 2026-09-11T19:16:20.839Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:56.003

Modified: 2026-09-11T20:19:23.217

Link: CVE-2026-89256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')