Stored Cross-Site Scripting in AVideo AD_Server Plugin
CVE-2026-88869
9.3CRITICAL
What is CVE-2026-88869?
The AVideo AD_Server plugin contains a stored cross-site scripting vulnerability in its log.php endpoint. This vulnerability arises from the failure to sanitize the 'label' parameter before storage, allowing unauthenticated attackers to inject malicious HTML. Once stored, this malicious content is rendered unsanitized in the admin Ad Types report using jQuery's .html() method, enabling the execution of arbitrary JavaScript within an administrator's browser session. This poses a significant risk to administrative accounts and the overall security of the AVideo platform.
Affected Version(s)
AVideo 0
