Cross-Site Scripting Vulnerability in WWBN AVideo YPTSocket Plugin
CVE-2026-34716

6.4MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34716?

The AVideo platform, an open source video service by WWBN, contains a vulnerability in its YPTSocket plugin. In versions 26.0 and earlier, the plugin improperly handles caller display names. By leveraging the jQuery Toast Plugin to render incoming call notifications, the plugin allows attackers to inject malicious HTML or JavaScript via the caller's display name. When a call is initiated, the toast notification is displayed without proper sanitization, enabling execution of embedded scripts in the browsers of connected users. This vulnerability can lead to unauthorized actions or data theft, emphasizing the necessity for vigilant security practices and timely updates.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.