Stored Cross-Site Scripting Vulnerability in WWBN AVideo Product
CVE-2026-105089
9.3CRITICAL
What is CVE-2026-105089?
WWBN AVideo versions up to 29.2.0 are susceptible to a stored cross-site scripting vulnerability. This issue arises when users with upload permissions can introduce malicious scripts via the trailer1 URL of uploaded videos. The unescaped value is processed within YouPHPFlix2 templates and channel playlists, enabling attackers to manipulate onclick strings or the src attributes of iframes, leading to the execution of arbitrary JavaScript code in the browsers of users who visit the compromised content. This vulnerability highlights the need for robust input validation and sanitization to prevent exploitation.
Affected Version(s)
AVideo 0 <= 29.2.0
