Product
WWBN AVideo versions 12.4 through 29.2.0 are vulnerable to stored cross-site scripting (XSS) due to improper sanitization of doubly-encoded HTML entities in video titles, allowing authenticated attackers to execute arbitrary scripts in the context of gallery and playlist pages.