CVE-2026-89254: AVideo CustomizeUser Stored XSS via field_name Parameter

Published Sep 11, 2026
·
Updated

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the fieldname parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php endpoint that execute when viewing extra info pages or profile forms that render the typeToHTML function.

Affected Software

1 affected component
AVideo CustomizeUser plugin

Event History

Sep 11, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs administrator-level access to submit a crafted field_name value to the CustomizeUser plugin's add.json.php endpoint. Exploitation also requires a user to view an extra info page or profile form that renders the affected typeToHTML function.

2

What is the impact after successful exploitation?

The injected script is stored and later executes in the browser of users viewing affected pages or forms. The reported impact includes high confidentiality and integrity impact, with scope changed; availability impact is not reported.

3

How can I determine whether an instance may be affected?

Review whether the AVideo CustomizeUser plugin includes commit c3edcc274c389816d434acadac07ee78eaf330c1 and whether administrators can use add.json.php to create custom fields. Check stored custom-field field_name values for unexpected HTML or script content, especially values that would be rendered on extra info pages or profile forms.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203