Stored Cross-Site Scripting Vulnerability in AVideo by WWBN
CVE-2026-88866

9.3CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88866?

The AVideo platform, specifically its LoginControl plugin, is affected by a stored cross-site scripting vulnerability. This issue arises from the plugin's failure to properly encode the User-Agent header before it is stored in the login history. This vulnerability allows attackers, using valid login credentials, to inject malicious scripts. When administrators view the Login History page, these scripts execute in their browsers, potentially compromising their sessions and opening pathways for further attacks. It's crucial for users of AVideo to address this vulnerability to protect against unauthorized access and manipulation.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.