Back

MEDIUM

WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page

Published Apr 7, 2026

Description

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a video's epg_link to a malicious XML file whose <title> elements contain JavaScript. This payload executes in the browser of any unauthenticated visitor to the public EPG page, enabling session hijacking and account takeover.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 7, 2026
Updated Apr 8, 2026
Reserved Apr 6, 2026
CISA Vulnrichment
Updated Apr 8, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-RQP3-GF5H-MRQX