Avideo · Avideo · CVE-2026-105086
**Name of the Vulnerable Software and Affected Versions**
AVideo versions 12.4 through 29.2.0
**Description**
Authenticated uploaders can perform a stored cross-site scripting attack by submitting doubly-encoded entities in video titles. The issue occurs because the `safeString()` function strips tags before decoding entities and is executed twice through the `setTitle()` and `save()` functions. This allows attackers to store HTML markup that executes on trending, gallery, embed, and playlist pages.
**Recommendations**
Update AVideo to a version later than 29.2.0.