CVE-2026-105086

Source
https://cve.org/CVERecord?id=CVE-2026-105086
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105086.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105086
Aliases
  • GHSA-q62w-927x-vhhf
Published
2026-10-04T15:10:23Z
Modified
2026-10-06T02:46:02Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
Details

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-79"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105086.json"
}
References

Affected packages

Git / github.com/wwbn/avideo

Affected ranges

Type
GIT
Repo
https://github.com/wwbn/avideo
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "12.4"
        },
        {
            "fixed":  "29.2.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

12.*
12.4
14.*
14.3
14.3.1
18.*
18.0
21.*
21.0
22.*
22.0
24.*
24.0
25.*
25.0
26.*
26.0
29.*
29.0
v29.*
v29.1.0
v29.1.1
v29.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105086.json"