CVE-2026-100630: Wwbn Avideo
Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.
AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators.
Affected products
- Wwbn Avideo: before 29.1.0 (fixed in 29.1.0)
Published 2026-09-26. Last modified 2026-10-04.