Stored Cross-Site Scripting in AVideo AD_Server Plugin
CVE-2026-88869

9.3CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88869?

The AVideo AD_Server plugin contains a stored cross-site scripting vulnerability in its log.php endpoint. This vulnerability arises from the failure to sanitize the 'label' parameter before storage, allowing unauthenticated attackers to inject malicious HTML. Once stored, this malicious content is rendered unsanitized in the admin Ad Types report using jQuery's .html() method, enabling the execution of arbitrary JavaScript within an administrator's browser session. This poses a significant risk to administrative accounts and the overall security of the AVideo platform.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.