CVE-2026-105089
Received Received - Intake

Stored XSS in WWBN AVideo via Malicious Video Trailer URL

Vulnerability report for CVE-2026-105089, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wwbn avideo to 29.2.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in WWBN AVideo through version 29.2.0. Users with upload permissions can inject malicious JavaScript code via the video trailer1 URL field. The injected code is not properly sanitized in certain templates like row_info.php and channelPlaylistItems.php, allowing attackers to execute arbitrary scripts in victims' browsers.

Detection Guidance

To detect this vulnerability, inspect AVideo installations for versions through 29.2.0. Check templates like row_info.php, BigVideoButtons.php, channelPlaylistItems.php, and BigVideo.php for improper escaping of the trailer1 field. Look for user-uploaded URLs containing JavaScript payloads or HTML entities in the trailer1 parameter.

Impact Analysis

Attackers can steal session cookies, perform actions on your behalf, or redirect you to malicious sites. Even administrators visiting a crafted page could have their sessions compromised. The vulnerability enables session-riding attacks and arbitrary script execution in user browsers.

Compliance Impact

This XSS vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles. For HIPAA, it may expose protected health information if exploited against healthcare-related deployments. Both standards require protection against such injection attacks.

Mitigation Strategies

Immediately update AVideo to the latest patched version. If updating is not possible, apply the GitHub commit c4adfde13d1f18e3a415722471efdcd8ab480035 which adds URL validation with isValidURL() and HTML escaping with htmlspecialchars(). Ensure trailer1 values are validated to reject non-http(s) URLs and special characters like quotes or angle brackets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105089. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart