Skip to content
Stored XSS Vulnerabilities in WWBN AVideo Disclosed

Stored XSS Vulnerabilities in WWBN AVideo Disclosed

First seen 4 Oct 2026, 21:02 UTC •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 22:01 UTC
  • •Two critical XSS vulnerabilities in WWBN AVideo versions up to 29.2.0.
  • •CVE-2026-105086 allows JavaScript injection via video titles.
  • •CVE-2026-105089 enables JavaScript injection through the trailer1 field.

Two stored cross-site scripting (XSS) vulnerabilities have been disclosed in WWBN AVideo versions up to 29.2.0. The first vulnerability (CVE-2026-105086) allows users with upload permissions to inject JavaScript via double-encoded video titles, affecting various views that echo unescaped content. The second vulnerability (CVE-2026-105089) enables JavaScript injection through the video trailer1 value, bypassing URL validation and affecting multiple templates. Both vulnerabilities have a CVSS score of 9.3, indicating severity. The flaws were disclosed on October 4, 2026, and remain in the affected versions. Administrators are urged to apply updates immediately to mitigate risks. These vulnerabilities could lead to malicious scripts running in the browsers of visitors and administrators alike.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
CVE-2026-105086 published
Stored XSS vulnerability disclosed allowing JavaScript injection via video titles, affecting multiple views.
github.com
2026-10-04
CVE-2026-105089 published
Stored XSS vulnerability disclosed allowing JavaScript injection through the trailer1 value, affecting several templates.
github.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-105086 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
WWBN AVideo versions up to 29.2.0 are affected by these vulnerabilities.
What is the severity of these vulnerabilities?
Both vulnerabilities have a CVSS score of 9.3, indicating critical severity.
What should administrators do?
Administrators should apply the latest updates to mitigate the risks associated with these vulnerabilities.