---
id: CVE-2026-105086
title: >-
  WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting
  vulnerability that allows authenticated uploaders to inject HTML by submitting
  doubly-encoded entities in video titles
summary: >-
  WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting
  vulnerability that allows authenticated uploaders to inject HTML by submitting
  doubly-encoded entities in video titles. Because safeString() strips tags
  before decodi…
severity: high
cvss: 8.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
vendor: WWBN
product: AVideo
affected:
  - AVideo >= 12.4 <= 29.2.0
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T16:16:30.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105086'
references:
  - url: >-
      https://github.com/WWBN/AVideo/commit/c4b6ca95a0ae3efa09919a98879870086cff150e
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-q62w-927x-vhhf'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/wwbn-avideo-12.4-through-29.2.0-stored-xss-via-double-encoded-video-title
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T16:01:19.148Z'
---

## Overview

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
