CVE-2026-41063: Wwbn Avideo
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URLs in markdown link syntax to bypass sanitization. Commit cae8f0dadbdd962c89b91d0095c76edb8aadcacf contains an updated fix.
Affected products
- Wwbn Avideo: up to and including 29.0
Published 2026-04-21. Last modified 2026-06-17.