CRITICAL 9.3 NVD

CVE-2026-88866

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails t

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allowing script execution within the administrator session.

References

Published: 2026-09-10 · Source: NVD · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-10 via NVD.

Risk Timeline

CVE Disclosed2026-09-10 · 0 days ago

Remediation Resources

vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.