Stored XSS Vulnerabilities in WWBN AVideo Disclosed
Article Content
- •Two critical XSS vulnerabilities in WWBN AVideo versions up to 29.2.0.
- •CVE-2026-105086 allows JavaScript injection via video titles.
- •CVE-2026-105089 enables JavaScript injection through the trailer1 field.
Two stored cross-site scripting (XSS) vulnerabilities have been disclosed in WWBN AVideo versions up to 29.2.0. The first vulnerability (CVE-2026-105086) allows users with upload permissions to inject JavaScript via double-encoded video titles, affecting various views that echo unescaped content. The second vulnerability (CVE-2026-105089) enables JavaScript injection through the video trailer1 value, bypassing URL validation and affecting multiple templates. Both vulnerabilities have a CVSS score of 9.3, indicating severity. The flaws were disclosed on October 4, 2026, and remain in the affected versions. Administrators are urged to apply updates immediately to mitigate risks. These vulnerabilities could lead to malicious scripts running in the browsers of visitors and administrators alike.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-105086 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
What is the severity of these vulnerabilities?
What should administrators do?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…