WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
PUBLISHED5.2CWE-79
WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
Problem type
Affected products
WWBN
AVideo
<= 29.2.0 - AFFECTED
References
GitHub Security Advisory (GHSA-q62w-927x-vhhf)
https://github.com/WWBN/AVideo/security/advisories/GHSA-q62w-927x-vhhf
Patch Commit
https://github.com/WWBN/AVideo/commit/c4b6ca95a0ae3efa09919a98879870086cff150e
VulnCheck Advisory: WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
https://www.vulncheck.com/advisories/wwbn-avideo-12.4-through-29.2.0-stored-xss-via-double-encoded-video-title
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-105086Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-105086",
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"dateUpdated": "2026-10-04T15:10:23.281Z",
"dateReserved": "2026-10-03T01:31:40.183Z",
"datePublished": "2026-10-04T15:10:23.281Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck",
"dateUpdated": "2026-10-04T15:10:23.281Z"
},
"datePublic": "2026-10-04T15:05:58.000Z",
"title": "WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title",
"descriptions": [
{
"lang": "en",
"value": "WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages."
}
],
"affected": [
{
"vendor": "WWBN",
"product": "AVideo",
"defaultStatus": "unaffected",
"versions": [
{
"version": "12.4",
"status": "affected",
"versionType": "custom",
"lessThanOrEqual": "29.2.0"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"cweId": "CWE-79",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/WWBN/AVideo/security/advisories/GHSA-q62w-927x-vhhf",
"name": "GitHub Security Advisory (GHSA-q62w-927x-vhhf)",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://github.com/WWBN/AVideo/commit/c4b6ca95a0ae3efa09919a98879870086cff150e",
"name": "Patch Commit",
"tags": [
"patch"
]
},
{
"url": "https://www.vulncheck.com/advisories/wwbn-avideo-12.4-through-29.2.0-stored-xss-via-double-encoded-video-title",
"name": "VulnCheck Advisory: WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title",
"tags": [
"third-party-advisory"
]
}
],
"metrics": [
{
"format": "CVSS"
},
{
"format": "CVSS",
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 8.7,
"baseSeverity": "HIGH"
}
}
],
"credits": [
{
"lang": "en",
"value": "Scott Moore - VulnCheck",
"type": "finder"
}
]
}
}
}