Act nowDisclosed

Advisory · CVE-2026-105086

AVideo video titles carry stored XSS past its sanitizer

AVideo's safeString() strips tags before decoding entities and runs twice, so doubly-encoded entities in video titles survive sanitization and execute as stored XSS on trending, gallery, embed, and playlist pages.

Vendor
WWBN
Product
AVideo
Identifier / CWE
CVE-2026-105086
CWE-79
Action timing
Immediate
ELI5

Explain it like I’m five

AVideo checks video titles for bad code, then unscrambles them, but it checks before the unscrambling, and it does the whole thing twice. An attacker writes a title that looks harmless at check time but turns into live code after the unscrambling, and everyone who views the video page runs it.

SIMPLIFIED_ATTACK_PATH04 STEPS
  1. 01Malicious title uploaded

    An authenticated uploader submits a video title containing doubly-encoded HTML entities.

  2. 02Sanitizer bypassed

    safeString() strips tags before decoding entities and runs twice via setTitle() and save(), so the markup survives and is stored.

  3. 03Title rendered elsewhere

    The stored title is rendered unescaped on trending, gallery, embed, and playlist pages.

  4. 04Script executes

    Visitors' browsers execute the attacker's JavaScript, enabling session theft or admin actions.

What happened

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability: authenticated uploaders can inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages. It is rated critical at CVSS 9.3 under CVSS v4.0 (8.7 under v3.1) and tracked as CWE-79.

What to do

  1. Upgrade AVideo past 29.2.0 to a release containing the vendor fix (per the vendor security advisory GHSA-q62w-927x-vhhf).
  2. Review recently uploaded videos for titles containing encoded entities or markup, and remove suspicious uploads.
  3. Check web and application logs for uploads with unusual title content from accounts that should not have upload permission.
  4. Force session resets for administrators and moderators if exploitation cannot be ruled out.

Management note

Stored XSS on a video platform turns every viewer into a potential victim and every uploader account into a launch pad. The sanitizer-bypass shape here means titles that passed review yesterday may still be live payloads today. Upgrade, then audit the content library rather than assuming the fix cleans up what is already stored.