PT-2026-104642 · Avideo · Avideo

·

CVE-2026-105089

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 29.2.0
Description A stored cross-site scripting issue exists where users with upload permissions can inject scripts by providing a malicious URL for the video trailer. This value is rendered without proper escaping in YouPHPFlix templates and channel playlists, enabling attackers to break out of onclick strings or iframe src attributes to execute JavaScript in the browsers of other users.
Recommendations Update to a version newer than 29.2.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105089
GHSA-6WFR-C7FW-4XVW

Affected Products

Avideo