CVE-2026-100630Medium· 5.4▾ SunlitAVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that b…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92584Medium· 6.1AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability
CVE-2026-89239Medium· 6.1WWBN AVideo Reflected XSS via Referer Header Comment Breakout
CVE-2026-89244Medium· 6.1WWBN AVideo Reflected XSS via Gallery Category getBackURL
CVE-2026-89249High· 8.7AVideo YPTWallet Stored XSS via CryptoWallet Configuration
CVE-2026-89254High· 8.7AVideo CustomizeUser Stored XSS via field_name Parameter
CVE-2026-89243High· 8.1WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input