Reflected Cross-Site Scripting Vulnerability in AVideo by WWBN
CVE-2026-85158
5.3MEDIUM
What is CVE-2026-85158?
AVideo contains a reflected cross-site scripting vulnerability in the videoEmbeded.php file, which improperly handles the link parameter. This issue arises from the lack of proper escaping for user input. When an attacker constructs a malicious embed URL and tricks a victim into visiting it, they can inject arbitrary JavaScript code that executes within the victim's browser. This could lead to a range of harmful effects, including data theft and session hijacking.
Affected Version(s)
AVideo 0
