
ExploitGrid Daily Digest 🚨 Top CVEs: CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-105135 (CVSS: 10) InternLM CVE-2026-103355 (CVSS: 9.3) Unlimited El... CVE-2026-105086 (CVSS: 9.3) wwbn CVE-2026-105089 (CVSS: 9.3) wwbn ..🧵👇
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

ExploitGrid Daily Digest 🚨 Top CVEs: CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-105135 (CVSS: 10) InternLM CVE-2026-103355 (CVSS: 9.3) Unlimited El... CVE-2026-105086 (CVSS: 9.3) wwbn CVE-2026-105089 (CVSS: 9.3) wwbn ..🧵👇

├ CVE-2026-105086 — WWBN AVideo · Stored XSS (double-encoded title) └ CVE-2026-105089 — WWBN AVideo · Stored XSS (YouPHPFlix2 templates)

[CVE] CVE-2026-105089 [HIGH PRIORITY] CVSS: 9.3 | Vendor: #wwbn #WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates 🔗 https://exploitgrid.net/cve/CVE-2026-105089

CVE-2026-105089 WWBN AVideo through 29.2.0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious vid… https://www.cve.org/CVERecord?id=CVE-2026-105089