PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105089 WWBN CVE debrief

A stored cross-site scripting vulnerability exists in WWBN AVideo through version 29.2.0, allowing users with upload permissions to inject malicious scripts via the video trailer1 URL. This script is rendered unescaped in YouPHPFlix2 templates and channel playlists, enabling attackers to execute JavaScript in victims' browsers. The vulnerability's high severity, with a CVSS score of 9.3, indicates a critical risk to systems with user-uploaded content or where users have permission to modify video trailers. Defenders should prioritize verification and remediation efforts, focusing on restricting upload permissions, validating user input, and implementing security measures like CSP.

Vendor
WWBN
Product
AVideo
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for systems with user-uploaded content, especially those with video sharing or community features, should assess exposure and prioritize remediation. This includes administrators of WWBN AVideo installations, security teams monitoring for XSS attacks, and developers integrating user-generated content.

Why it matters

CVE-2026-105089 is a critical stored cross-site scripting vulnerability in WWBN AVideo that allows attackers to inject malicious scripts into video trailers. Defenders should prioritize verification and remediation, especially for systems with user-uploaded content or where users have permission to modify video trailers. The vulnerability's CVSS score of 9.3 indicates a high severity level, and exploitation could lead to significant impacts on affected systems.

  • Execution of arbitrary JavaScript in users' browsers, potentially leading to account takeovers or further exploitation.
  • Defacement or modification of video content, affecting the integrity of the platform.
  • Theft of sensitive information, such as user credentials or session tokens.
  • Potential for phishing or social engineering attacks through injected content.

Technical summary

The vulnerability exists in the way WWBN AVideo handles user-uploaded video trailers. An attacker with upload permissions can inject malicious JavaScript code by setting a malicious video trailer1 URL. This code is then rendered unescaped in YouPHPFlix2 templates and channel playlists, allowing the attacker to execute JavaScript in victims' browsers. The vulnerability is highly severe, with a CVSS score of 9.3, indicating a high risk of exploitation. Defenders should focus on validating user input, restricting upload permissions, and implementing security measures like CSP to mitigate the risk. The CVE record and NVD entry provide details on the vulnerability, but specific details about affected versions or rem

Defensive priority

Defenders should prioritize verifying and remediating this vulnerability, especially for systems with user-uploaded content or where users have permission to modify video trailers.

Recommended defensive actions

  • Verify the version of WWBN AVideo in use and check for user-uploaded content or video trailers that could be exploited.
  • Restrict upload permissions to trusted users and validate user input for video trailers.
  • Implement Content Security Policy (CSP) and other security measures to mitigate XSS attacks.
  • Monitor for suspicious activity or anomalies in user behavior related to video uploads or modifications.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its CVSS score of 9.3 and a description of the attack vector. However, specific details about affected versions, exploitation, or remediation are limited.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105089 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105089

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105089 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105089

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.