CVE-2026-105086: WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title

Published Oct 4, 2026
·
Updated

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

Affected Software

1 affected component
WWBN AVideo>=12.4<=29.2.0

Event History

Oct 4, 2026
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is exposed to the injected content?

An authenticated user with permission to upload videos can submit a malicious video title. Users who view affected trending, gallery, embed, or playlist pages can be exposed to the stored markup.

2

What input is required to trigger the vulnerability?

The attacker must submit HTML in a video title using doubly encoded entities. The issue occurs because tags are stripped before entities are decoded, and the title processing runs twice during setTitle() and save().

3

Are sites affected without enabling a special feature?

The vulnerable behavior is in video-title handling and affects the listed display locations: trending, gallery, embed, and playlist pages. The available information does not identify any separate optional feature or configuration prerequisite.

4

How can I determine whether my deployment is affected?

Deployments running WWBN AVideo versions 12.4 through 29.2.0 are within the affected range. Review video titles submitted by authenticated uploaders, especially titles containing doubly encoded HTML entities, and check the affected page types for rendered markup.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203