PT-2026-51177 · Avideo · Avideo Topmenu

·

CVE-2026-56347

·

Published

2026-04-01

·

Updated

2026-06-20

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo TopMenu plugin versions prior to 26.1
Description A stored cross-site scripting issue exists in menu item rendering caused by missing output encoding of icon classes, URLs, and text labels. This allows attackers to inject malicious JavaScript through unescaped menu item fields, which then executes for all site visitors. This can lead to the theft of session cookies or the performance of unauthorized actions.
Recommendations Update the AVideo TopMenu plugin to a version later than 26.0.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56347
GHSA-GMPC-FXG2-VCMQ

Affected Products

Avideo Topmenu