Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Xfscott

#15971of 57,490
18.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2026-104641
9.3
2026-10-04
Avideo · Avideo · CVE-2026-105086
**Name of the Vulnerable Software and Affected Versions** AVideo versions 12.4 through 29.2.0 **Description** Authenticated uploaders can perform a stored cross-site scripting attack by submitting doubly-encoded entities in video titles. The issue occurs because the `safeString()` function strips tags before decoding entities and is executed twice through the `setTitle()` and `save()` functions. This allows attackers to store HTML markup that executes on trending, gallery, embed, and playlist pages. **Recommendations** Update AVideo to a version later than 29.2.0.
PT-2026-104642
9.3
2026-10-04
Avideo · Avideo · CVE-2026-105089
**Name of the Vulnerable Software and Affected Versions** AVideo versions prior to 29.2.0 **Description** A stored cross-site scripting issue exists where users with upload permissions can inject scripts by providing a malicious URL for the video trailer. This value is rendered without proper escaping in YouPHPFlix templates and channel playlists, enabling attackers to break out of `onclick` strings or `iframe` `src` attributes to execute JavaScript in the browsers of other users. **Recommendations** Update to a version newer than 29.2.0.