
ExploitGrid Daily Digest 🚨 Top CVEs: CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-105135 (CVSS: 10) InternLM CVE-2026-103355 (CVSS: 9.3) Unlimited El... CVE-2026-105086 (CVSS: 9.3) wwbn CVE-2026-105089 (CVSS: 9.3) wwbn ..🧵👇
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

ExploitGrid Daily Digest 🚨 Top CVEs: CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-105135 (CVSS: 10) InternLM CVE-2026-103355 (CVSS: 9.3) Unlimited El... CVE-2026-105086 (CVSS: 9.3) wwbn CVE-2026-105089 (CVSS: 9.3) wwbn ..🧵👇

├ CVE-2026-105086 — WWBN AVideo · Stored XSS (double-encoded title) └ CVE-2026-105089 — WWBN AVideo · Stored XSS (YouPHPFlix2 templates)

[CVE] CVE-2026-105086 [HIGH PRIORITY] CVSS: 9.3 | Vendor: #wwbn #WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title 🔗 https://exploitgrid.net/cve/CVE-2026-105086

CVE-2026-105086 WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded… https://www.cve.org/CVERecord?id=CVE-2026-105086