Cross-Site Scripting Vulnerability in AVideo Admin Panel
CVE-2026-34396

6.1MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34396?

AVideo, an open-source video platform, contains a security vulnerability that allows attackers to exploit the admin panel. In versions 26.0 and earlier, the plugin configuration values are rendered in HTML forms without proper output encoding, such as htmlspecialchars(). The jsonToFormElements() function in admin/functions.php can be manipulated to include user-controlled values directly into form fields. This weakness enables an attacker, either as a compromised admin or by leveraging a CSRF attack on admin/save.json.php, to inject arbitrary JavaScript code that executes upon any administrator accessing the plugin configuration page. No patches are currently available to mitigate this vulnerability.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.