CVE-2026-105086: fallo crítico en WWBN AVideo
WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
Publicada el · Actualizada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3epss 0.2%
probabilidad de explotación
0.2%top 87% de las CVE
explotación observada
noninguna fuente lo reporta
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Productos afectados
WWBN · AVideoCVEs relacionadas — WWBN AVideo
En el mismo producto, de las más peligrosas a las menos.
CVE-2022-30690CRITICALCVE-2022-30690EPSS 83.9%CVE-2022-30534CRITICALCVE-2022-30534EPSS 75.0%CVE-2022-30547CRITICALCVE-2022-30547EPSS 63.7%CVE-2022-32572CRITICALCVE-2022-32572EPSS 24.4%CVE-2026-33478CRITICALAVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command InjectionEPSS 11.2%CVE-2023-32073HIGHAVideo command injection vulnerabilityEPSS 6.5%