The AVideo open-source video platform has security vulnerabilities in versions 29.0 and below that allow arbitrary HTML/JavaScript injection.
Claims
The AVideo open-source video platform has security vulnerabilities in versions 29.0 and below that allow arbitrary HTML/JavaScript injection.
Parent: CybersecurityEntity: AVideo open-source video platformImpact: negativeDate: Apr 22, 2026Target: The AVideo open-source video platform has security vulnerabilities in versions 29.0 and below that allow arbitrary HTML/JavaScript injection.
Source posts
๐จ EUVD-2026-24539
๐ Score: 5.4/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor, allowing arbitrary HTML/JavaScript to be appended after a vali...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24539
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24543
๐ Score: 5.4/10 (CVSS v3.1)
๐ฆ Product: AVideo
๐ข Vendor: WWBN
๐
Updated: 2026-04-21
๐ WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URL...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24543
#cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability