Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-88868: AVideo LiveLinks lets attackers run scripts on viewers
CVE-2026-88868 · published 19 days ago
Summary
The LiveLinks feature in AVideo does not clean up the title and description you enter. This means someone with streaming rights could add code that runs in the browsers of anyone who watches the live link, including administrators. Limit who can create live links, apply input filtering, or upgrade to a version where the issue is fixed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| wwbn | avideo | <= c3edcc274c389816d434acadac07ee78eaf330c1 |
Original advisory text
AVideo LiveLinks Stored XSS via title and description fields
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including administrators, within the site origin.
Severity
9.3
Critical
CVSS 3.1: 8.7 (MITRE)
Exploitation
EPSS <1%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published10 Sep 2026
Updated27 Sep 2026
First seen10 Sep 2026
Track software like this
Free during beta