CVE-2026-72747

Source
https://cve.org/CVERecord?id=CVE-2026-72747
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72747.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72747
Aliases
  • GHSA-cfvq-r985-84wj
Published
2026-08-11T12:17:01Z
Modified
2026-09-10T03:30:49Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
AVideo Stored Cross-Site Scripting via Unauthenticated Registration
Details

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72747.json"
}
References

Affected packages

Git / github.com/wwbn/avideo

Affected ranges

Type
GIT
Repo
https://github.com/wwbn/avideo
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "29.0"
        },
        {
            "last_affected": "29.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

29.*
29.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72747.json"