MEDIUM 5.3 NVD
CVE-2026-89241
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copi
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute and inject event handlers that execute in the victim's browser within the site origin.
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-fp9p-hrc9-8rr7
- https://www.vulncheck.com/advisories/wwbn-avideo-reflected-xss-via-confirmlivepassword-php
- https://github.com/WWBN/AVideo/security/advisories/GHSA-fp9p-hrc9-8rr7
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-11 via NVD.
vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.