CVE-2026-105086: WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue, and who is exposed to the injected content?
An authenticated user with permission to upload videos can submit a malicious video title. Users who view affected trending, gallery, embed, or playlist pages can be exposed to the stored markup.
What input is required to trigger the vulnerability?
The attacker must submit HTML in a video title using doubly encoded entities. The issue occurs because tags are stripped before entities are decoded, and the title processing runs twice during setTitle() and save().
Are sites affected without enabling a special feature?
The vulnerable behavior is in video-title handling and affects the listed display locations: trending, gallery, embed, and playlist pages. The available information does not identify any separate optional feature or configuration prerequisite.
How can I determine whether my deployment is affected?
Deployments running WWBN AVideo versions 12.4 through 29.2.0 are within the affected range. Review video titles submitted by authenticated uploaders, especially titles containing doubly encoded HTML entities, and check the affected page types for rendered markup.