VYPR

AVideo

by AVideo

CVEs (1)

  • CVE-2026-49279higJun 4, 2026
    risk 0.38cvss epss

    # AVideo: Stored XSS via `autoEvalCodeOnHTML` in MessageSQLite WebSocket Handler ## Summary AVideo has a stored XSS vulnerability in the WebSocket messaging system. The `MessageSQLite.php` handler only strips `autoEvalCodeOnHTML` from `$json['msg']`, but `msgToResourceId()`…