PT-2026-104641 · Avideo · Avideo

·

CVE-2026-105086

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions 12.4 through 29.2.0
Description Authenticated uploaders can perform a stored cross-site scripting attack by submitting doubly-encoded entities in video titles. The issue occurs because the safeString() function strips tags before decoding entities and is executed twice through the setTitle() and save() functions. This allows attackers to store HTML markup that executes on trending, gallery, embed, and playlist pages.
Recommendations Update AVideo to a version later than 29.2.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105086
GHSA-Q62W-927X-VHHF

Affected Products

Avideo