CVE-2026-89256
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every visitor of that video executes the payload in the AVideo origin.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
- EPSS probability
- 0.32%
- CWE
- CWE-79
- Published
- 2026-09-11
- Last modified
- 2026-09-11
Affected products
- WWBN AVideo
Weakness type
Related vulnerabilities
- CVE-2026-78252 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-88866 — WWBN AVideo LoginControl Stored XSS via User-Agent Header
- CVE-2026-90943 — parallax filament-comments through 3.0.0 Stored XSS via Comment Body
- CVE-2026-90561 — Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
- CVE-2026-89255 — AVideo LoginControl Stored XSS via PGP Public Key
- CVE-2026-89254 — AVideo CustomizeUser Stored XSS via field_name Parameter
- CVE-2026-89253 — AVideo Stored XSS via donationLink in watch page button