VYPR
High severity8.7NVD Advisory· Published Sep 11, 2026

CVE-2026-89255

CVE-2026-89255

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which executes in an administrator's session when viewing the user's profile tab.

Affected products

1
  • WWBN/Avideollm-fuzzy
    Range: <c3edcc274c389816d434acadac07ee78eaf330c1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.