medium · CVSS v3 5.4 · CVSS v4 5.1
CVE-2026-100630
AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an i…
Description
AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators.
Scores
- Severity
- medium
- CVSS v2
- 5.5
- CVSS v3
- 5.4
- CVSS v4
- 5.1
- EPSS
- —