CVE-2026-105086

LOWCVSS 9.3 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-10-05)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-10-04: 1Mentions · 2026-10-05: 310-0410-05
Referenced assets2 URLs
Full discourse4 posts
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top CVEs: CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-105135 (CVSS: 10) InternLM CVE-2026-103355 (CVSS: 9.3) Unlimited El... CVE-2026-105086 (CVSS: 9.3) wwbn CVE-2026-105089 (CVSS: 9.3) wwbn ..🧵👇

    11060346
    361 followersView on X
  • ExploitGrid@exploitgrid

    ├ CVE-2026-105086 — WWBN AVideo · Stored XSS (double-encoded title) └ CVE-2026-105089 — WWBN AVideo · Stored XSS (YouPHPFlix2 templates)

    1000024
    361 followersView on X
  • ExploitGrid@exploitgrid

    [CVE] CVE-2026-105086 [HIGH PRIORITY] CVSS: 9.3 | Vendor: #wwbn #WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title 🔗 https://exploitgrid.net/cve/CVE-2026-105086

    1000039
    361 followersView on X
  • CVE@CVEnew

    CVE-2026-105086 WWBN AVideo 12.4 through 29.2.0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded… https://www.cve.org/CVERecord?id=CVE-2026-105086

    000001.1K
    58.1K followersView on X

Explore more