{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/avideo-12.4-through-29.2.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-105086"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AVideo (12.4 through 29.2.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WWBN"],"content_html":"\u003cp\u003eWWBN AVideo, an open-source video platform, contains a stored cross-site scripting (XSS) vulnerability affecting versions 12.4 through 29.2.0 (CVE-2026-105086). The vulnerability arises from an improper input sanitization process involving the safeString() function. The application attempts to strip malicious HTML tags before decoding entities. However, due to a double-encoding flaw where entities are processed twice by the setTitle() and save() methods, an authenticated user can bypass these security checks. By submitting video titles containing doubly-encoded HTML entities, an attacker can store malicious JavaScript markup within the application database. This payload is subsequently rendered and executed when other users or administrators visit pages such as trending, gallery, embed, or playlist views. This vulnerability is significant as it allows for session hijacking, credential theft, or unauthorized actions performed on behalf of legitimate users who interact with the infected video content.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to inject and execute arbitrary JavaScript in the browsers of other users viewing the application. Potential consequences include the compromise of user sessions, theft of sensitive cookies, or unauthorized modification of application data. The vulnerability affects a broad range of AVideo versions (12.4 to 29.2.0), potentially impacting any organization hosting this video platform for internal or external media distribution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate WWBN AVideo to a version beyond 29.2.0 that includes the security patch for CVE-2026-105086.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, implement strict input validation on the application's video metadata upload API to block doubly-encoded entities.\u003c/li\u003e\n\u003cli\u003eAudit application logs for suspicious activity on the video upload and metadata management endpoints.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected requests to the trending, gallery, or playlist pages that contain script-related characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-04T16:54:10Z","date_published":"2026-10-04T16:54:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-avideo-stored-xss/","summary":"WWBN AVideo versions 12.4 through 29.2.0 are vulnerable to stored cross-site scripting (XSS) due to improper sanitization of doubly-encoded HTML entities in video titles, allowing authenticated attackers to execute arbitrary scripts in the context of gallery and playlist pages.","title":"Stored Cross-Site Scripting in WWBN AVideo via Video Titles","url":"https://feed.craftedsignal.io/briefs/2026-10-avideo-stored-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - AVideo (12.4 Through 29.2.0)","version":"https://jsonfeed.org/version/1.1"}