Stored Cross-Site Scripting in AVideo Bookmark Plugin
CVE-2026-89256
9.3CRITICAL
What is CVE-2026-89256?
AVideo's Bookmark plugin contains a stored cross-site scripting vulnerability where chapter names are improperly handled. This oversight allows an attacker to inject malicious scripts through the bookmark name parameter, potentially impacting all visitors who access the video and execute the payload in the AVideo environment. It is vital for administrators to review and mitigate these security loopholes to protect users from exploitation.
Affected Version(s)
AVideo 0
