CVE-2026-105086
Received Received - Intake

Stored XSS in AVideo via Doubly-Encoded Entities in Titles

Vulnerability report for CVE-2026-105086, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wwbn avideo From 12.4 (inc) to 29.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in WWBN AVideo versions 12.4 through 29.2.0. Authenticated users with upload privileges can inject malicious HTML by submitting doubly-encoded entities in video titles. The safeString() function strips HTML tags before decoding entities, and this process runs twice during title setting and saving. This allows attackers to store markup that executes in trending, gallery, embed, and playlist pages.

Detection Guidance

Check AVideo versions between 12.4 and 29.2.0 for vulnerable installations. Inspect video titles and descriptions for doubly-encoded entities like <img>. Review server logs for unusual HTML tag patterns in user-uploaded content. Use grep to search for safeString() and setTitle() functions in PHP files.

Impact Analysis

An attacker with upload access could inject malicious scripts that execute when videos are viewed on public pages. This could lead to session hijacking, administrative actions if an admin's session is compromised, or other malicious activities like data theft or defacement. The impact depends on user privileges and the actions taken by the injected script.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. If exploited, it may result in data breaches, non-compliance with privacy regulations, and potential legal consequences. Organizations using affected AVideo versions should patch immediately to maintain compliance.

Mitigation Strategies

Upgrade to the latest patched version of AVideo. Apply the GitHub commit c4b6ca95a0ae3efa09919a98879870086cff150e to sanitize video titles and descriptions. Ensure safeString() decodes entities before stripping tags. Escape output using htmlspecialchars() with ENT_QUOTES in all affected pages.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105086. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart