โ† All reports

The AVideo open-source video platform has security vulnerabilities in versions 29.0 and below that allow arbitrary HTML/JavaScript injection.

CybersecurityTechnologyConflictApr 22, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the AVideo open-source video platform developed by WWBN, both related to security flaws that allow arbitrary HTML/JavaScript injection. These vulnerabilities affect versions 29.0 and below and pose a risk to users' security.

Claims

The AVideo open-source video platform has security vulnerabilities in versions 29.0 and below that allow arbitrary HTML/JavaScript injection.
Parent: CybersecurityEntity: AVideo open-source video platformImpact: negativeDate: Apr 22, 2026Target: The AVideo open-source video platform has security vulnerabilities in versions 29.0 and below that allow arbitrary HTML/JavaScript injection.

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24539 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor, allowing arbitrary HTML/JavaScript to be appended after a vali... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24539 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24543 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AVideo ๐Ÿข Vendor: WWBN ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URL... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24543 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability