CVE-2026-45580

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream key into an HTML class attribute by raw echo, without htmlspecialchars(). A canStream user can persist a key containing " plus an event handler via plugin/Live/saveLive.php, and any visitor (logged in or anonymous) opening the stream's live page executes attacker JavaScript in the platform origin.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) WWBN AVideo es una plataforma de video de código abierto. En 29.0 y anteriores, existe una vulnerabilidad de cross-site scripting almacenado. La vista 'estilo YouTube' del plugin Live renderiza la clave de transmisión de la transmisión en vivo en un atributo de clase HTML mediante un echo sin procesar, sin htmlspecialchars(). Un usuario canStream puede persistir una clave que contenga ' más un gestor de eventos a través de plugin/Live/saveLive.php, y cualquier visitante (autenticado o anónimo) que abra la página en vivo del stream ejecuta JavaScript del atacante en el origen de la plataforma.

01 Jun 2026, 18:41

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-m5j4-7r85-2cj2 - () https://github.com/WWBN/AVideo/security/advisories/GHSA-m5j4-7r85-2cj2 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
First Time Wwbn
Wwbn avideo

29 May 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 14:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-45580

Mitre link : CVE-2026-45580

CVE.ORG link : CVE-2026-45580


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')