Stored Cross-Site Scripting Risk in AVideo's LoginControl Plugin
CVE-2026-89255
9.3CRITICAL
What is CVE-2026-89255?
The AVideo LoginControl plugin is subject to a serious stored cross-site scripting vulnerability. This occurs when an authenticated user submits a specially crafted PGP public key that is not properly HTML-encoded when rendered in a textarea element. As a result, the injected malicious JavaScript can execute in the administrator's session, particularly when the profile tab is viewed. This can lead to unauthorized actions or data exfiltration if successfully exploited.
Affected Version(s)
AVideo 0
