Stored Cross-Site Scripting in AVideo by WWBN
CVE-2026-92584
5.3MEDIUM
What is CVE-2026-92584?
AVideo versions up to 29.0 are susceptible to a stored cross-site scripting vulnerability via the video view counter endpoint. The application's failure to sanitize the User-Agent string allows attackers to inject malicious HTML that gets executed in the context of the administrator's session when the statistics page is viewed. This vulnerability poses a significant risk as it can lead to unauthorized actions being performed in privileged user sessions.
Affected Version(s)
AVideo 0 <= 29.0
