#VU125448 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in AVideo - CVE-2026-33295
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote user to execute arbitrary JavaScript in the browser of another user.
The vulnerability exists due to cross-site scripting in the CDN plugin downloadButtons.php component when rendering the user-supplied clean_title field into a JavaScript string literal on the download page. A remote user can create or modify a video with a specially crafted title to execute arbitrary JavaScript in the browser of another user.
User interaction is required, as a victim must visit the affected download page for the attacker-controlled video.