---
id: CVE-2026-84477
title: >-
  AVideo Live_schedule::setTitle() and setDescription() store POST input without
  sanitization, allowing users with streaming permission to inject malicious
  scripts
summary: >-
  AVideo Live_schedule::setTitle() and setDescription() store POST input without
  sanitization, allowing users with streaming permission to inject malicious
  scripts. Unauthenticated attackers can access remindMe.php to execute stored
  XSS pa…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-09-01'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:18:59.270'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84477'
references:
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-625v-vrhq-g274'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/avideo-stored-xss-via-live-schedule-title-description
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-625v-vrhq-g274'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00292
epssPercentile: 0.19322
ingestedAt: '2026-09-08T21:11:12.289Z'
---

## Overview

AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
