← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 4, 2026 · 16:16via CVEFeed

CVE-2026-105086 - WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title

Brief

CVE ID : CVE-2026-105086

Published : Oct. 4, 2026, 4:16 p. m.

  • 3 hours, 15 minutes ago

Description : WWBN AVideo 12. 4 through 29.

  • 0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

Severity: 9.3

  • CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→