Stored Cross-Site Scripting in WWBN AVideo via Video Titles
WWBN AVideo versions 12.4 through 29.2.0 are vulnerable to stored cross-site scripting (XSS) due to improper sanitization of doubly-encoded HTML entities in video titles, allowing authenticated attackers to execute arbitrary scripts in the context of gallery and playlist pages.
CVE search metadata
CVE search record: CVE-2026-105086. Severity: high. CVSS: 8.7. KEV: no. Product: AVideo (12.4 through 29.2.0). Brief: Stored Cross-Site Scripting in WWBN AVideo via Video Titles. Brief link: https://feed.craftedsignal.io/briefs/2026-10-avideo-stored-xss/
WWBN AVideo, an open-source video platform, contains a stored cross-site scripting (XSS) vulnerability affecting versions 12.4 through 29.2.0 (CVE-2026-105086). The vulnerability arises from an improper input sanitization process involving the safeString() function. The application attempts to strip malicious HTML tags before decoding entities. However, due to a double-encoding flaw where entities are processed twice by the setTitle() and save() methods, an authenticated user can bypass these security checks. By submitting video titles containing doubly-encoded HTML entities, an attacker can store malicious JavaScript markup within the application database. This payload is subsequently rendered and executed when other users or administrators visit pages such as trending, gallery, embed, or playlist views. This vulnerability is significant as it allows for session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users who interact with the infected video content.
Impact
Successful exploitation allows authenticated attackers to inject and execute arbitrary JavaScript in the browsers of other users viewing the application. Potential consequences include the compromise of user sessions, theft of sensitive cookies, or unauthorized modification of application data. The vulnerability affects a broad range of AVideo versions (12.4 to 29.2.0), potentially impacting any organization hosting this video platform for internal or external media distribution.
Recommendation
- Update WWBN AVideo to a version beyond 29.2.0 that includes the security patch for CVE-2026-105086.
- Until patching is possible, implement strict input validation on the application's video metadata upload API to block doubly-encoded entities.
- Audit application logs for suspicious activity on the video upload and metadata management endpoints.
- Monitor for unexpected requests to the trending, gallery, or playlist pages that contain script-related characters.
Immediate actions
Patch WWBN AVideo to the latest version to address CVE-2026-105086.
Threat Hunt
Search web server logs for requests to video upload endpoints containing encoded HTML entities or script tags.
Data: webserver access logs