CVE-2026-34396 is a Cross-Site Scripting (XSS) vulnerability affecting WWBN AVideo versions 26.0 and prior. It arises from the admin panel's failure to properly encode user-controlled plugin configuration values, allowing for arbitrary JavaScript injection. Rated Medium severity (CVSS 6.1), this vulnerability can be exploited by an unauthenticated attacker who successfully chains with a Cross-Site Request Forgery (CSRF) attack targeting an administrator. The injected JavaScript executes when an administrator visits the affected plugin configuration page, potentially leading to client-side compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this CVE, and no patches are available at the time of this briefing.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.