Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators. | AVideo before 29.1.0 contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators. |
| Title | AVideo Stored XSS via HTML Entity Bypass in trailer1 Field | AVideo before 29.1.0 Stored XSS via HTML Entity Bypass in trailer1 Field |
| References |
|
Wed, 30 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators. | |
| Title | AVideo Stored XSS via HTML Entity Bypass in trailer1 Field | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-03T23:44:08.065Z
Reserved: 2026-09-26T02:31:42.100Z
Link: CVE-2026-100630
Updated: 2026-09-30T13:00:06.206Z
Status : Awaiting Analysis
Published: 2026-09-26T14:16:44.260
Modified: 2026-10-04T00:16:35.393
Link: CVE-2026-100630
No data.
OpenCVE Enrichment
Updated: 2026-10-04T02:30:06Z