CVE-2026-33295 Details
Description
WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly into a JavaScript string literal without any escaping, allowing an attacker who can create or modify a video to inject arbitrary JavaScript that executes in the browser of any user who visits the affected download page. Version 26.0 fixes the issue.
A stored cross-site scripting vulnerability has been identified in WWBN AVideo versions prior to 26.0, specifically within the CDN plugin's download buttons component. The issue arises because the 'clean_title' field of a video record is directly inserted into a JavaScript string literal without proper escaping. This flaw allows an attacker with the ability to create or modify videos to inject arbitrary JavaScript. The injected script executes in the browser of any user who visits the affected download page.
Users can update to WWBN AVideo version 26.0 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WWBN/AVideo/security/advisories/GHSA-gc3m-4mcr-h3pv | CISA-ADP | ExploitVendor Advisory |
| https://github.com/WWBN/AVideo/commit/30cdd825fa5778c1d678c2402be2413b84ee4833 | [email protected] | Patch |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-gc3m-4mcr-h3pv | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wwbn avideo | < 26.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 24, 2026 | Initial Analysis | [email protected] |
| Mar 23, 2026 | CVE Modified | CISA-ADP |
| Mar 22, 2026 | New CVE Received | [email protected] |