Stored Cross-Site Scripting Vulnerability in WWBN AVideo Product
CVE-2026-105089

9.3CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
4 October 2026

What is CVE-2026-105089?

WWBN AVideo versions up to 29.2.0 are susceptible to a stored cross-site scripting vulnerability. This issue arises when users with upload permissions can introduce malicious scripts via the trailer1 URL of uploaded videos. The unescaped value is processed within YouPHPFlix2 templates and channel playlists, enabling attackers to manipulate onclick strings or the src attributes of iframes, leading to the execution of arbitrary JavaScript code in the browsers of users who visit the compromised content. This vulnerability highlights the need for robust input validation and sanitization to prevent exploitation.

Affected Version(s)

AVideo 0 <= 29.2.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Scott Moore - VulnCheck
.