PatchSiren cyber security CVE debrief
CVE-2026-105089 WWBN CVE debrief
A stored cross-site scripting vulnerability exists in WWBN AVideo through version 29.2.0, allowing users with upload permissions to inject malicious scripts via the video trailer1 URL. This script is rendered unescaped in YouPHPFlix2 templates and channel playlists, enabling attackers to execute JavaScript in victims' browsers. The vulnerability's high severity, with a CVSS score of 9.3, indicates a critical risk to systems with user-uploaded content or where users have permission to modify video trailers. Defenders should prioritize verification and remediation efforts, focusing on restricting upload permissions, validating user input, and implementing security measures like CSP.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for systems with user-uploaded content, especially those with video sharing or community features, should assess exposure and prioritize remediation. This includes administrators of WWBN AVideo installations, security teams monitoring for XSS attacks, and developers integrating user-generated content.
Why it matters
CVE-2026-105089 is a critical stored cross-site scripting vulnerability in WWBN AVideo that allows attackers to inject malicious scripts into video trailers. Defenders should prioritize verification and remediation, especially for systems with user-uploaded content or where users have permission to modify video trailers. The vulnerability's CVSS score of 9.3 indicates a high severity level, and exploitation could lead to significant impacts on affected systems.
- Execution of arbitrary JavaScript in users' browsers, potentially leading to account takeovers or further exploitation.
- Defacement or modification of video content, affecting the integrity of the platform.
- Theft of sensitive information, such as user credentials or session tokens.
- Potential for phishing or social engineering attacks through injected content.
Technical summary
The vulnerability exists in the way WWBN AVideo handles user-uploaded video trailers. An attacker with upload permissions can inject malicious JavaScript code by setting a malicious video trailer1 URL. This code is then rendered unescaped in YouPHPFlix2 templates and channel playlists, allowing the attacker to execute JavaScript in victims' browsers. The vulnerability is highly severe, with a CVSS score of 9.3, indicating a high risk of exploitation. Defenders should focus on validating user input, restricting upload permissions, and implementing security measures like CSP to mitigate the risk. The CVE record and NVD entry provide details on the vulnerability, but specific details about affected versions or rem
Defensive priority
Defenders should prioritize verifying and remediating this vulnerability, especially for systems with user-uploaded content or where users have permission to modify video trailers.
Recommended defensive actions
- Verify the version of WWBN AVideo in use and check for user-uploaded content or video trailers that could be exploited.
- Restrict upload permissions to trusted users and validate user input for video trailers.
- Implement Content Security Policy (CSP) and other security measures to mitigate XSS attacks.
- Monitor for suspicious activity or anomalies in user behavior related to video uploads or modifications.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 9.3 and a description of the attack vector. However, specific details about affected versions, exploitation, or remediation are limited.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105089 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105089
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105089 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105089
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/commit/c4adfde13d1f18e3a415722471efdcd8ab480035
-
Source reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/security/advisories/GHSA-6wfr-c7fw-4xvw
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/wwbn-avideo-through-29.2.0-stored-xss-via-trailer1-in-youphpflix2-templates
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.