Cross-Site Scripting Vulnerability in WWBN AVideo YPTSocket Plugin
CVE-2026-34716
6.4MEDIUM
What is CVE-2026-34716?
The AVideo platform, an open source video service by WWBN, contains a vulnerability in its YPTSocket plugin. In versions 26.0 and earlier, the plugin improperly handles caller display names. By leveraging the jQuery Toast Plugin to render incoming call notifications, the plugin allows attackers to inject malicious HTML or JavaScript via the caller's display name. When a call is initiated, the toast notification is displayed without proper sanitization, enabling execution of embedded scripts in the browsers of connected users. This vulnerability can lead to unauthorized actions or data theft, emphasizing the necessity for vigilant security practices and timely updates.
Affected Version(s)
AVideo <= 26.0
