CVE-2026-105089

CVE-2026-105089 published: WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlis...

View full NVD advisory → ← Back to CVE watch