Medium severity5.4NVD Advisory· Published Sep 11, 2026
CVE-2026-89246
CVE-2026-89246
Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated users can inject formulas starting with =, +, -, or @ characters that execute when administrators or video owners open the exported CSV file in spreadsheet applications.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.