{"id":"CVE-2026-100630","published":"2026-09-26T14:16:44.260","lastModified":"2026-09-28T20:53:43.443","description":"AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an inline onclick JavaScript string. Attackers with video upload permission can store HTML entity-encoded payloads that bypass isValidURL() validation and are decoded by the browser to break out of the JavaScript string, executing arbitrary code in any visitor's session including administrators.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-v7vx-v9q9-qhw3","tags":[]},{"url":"https://www.vulncheck.com/advisories/avideo-stored-xss-via-html-entity-bypass-in-trailer1-field","tags":[]}],"exploitRefs":[{"url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-v7vx-v9q9-qhw3","tags":[]}],"hasPoc":true,"ai":null}