Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39367

23
FAUCET Score

OVERVIEW CVE-2026-39367 is a stored cross-site scripting (XSS) vulnerability affecting WWBN AVideo version 26.0 and prior. The vulnerability exists in the EPG (Electronic Program Guide) feature, which parses XML from user-controlled URLs without proper sanitization. An attacker with upload permissions can inject malicious JavaScript code into XML title elements, which executes when unauthenticated visitors view the public EPG page. SEVERITY The vulnerability requires network access and low privilege (upload permission) but presents straightforward attack complexity. With a CVSS score of 5.4 (Medium), the impact includes low confidentiality and integrity risk through session hijacking and potential account takeover of administrative or authenticated users. The attack requires user interaction (victims must visit the EPG page), and the scope is changed, meaning the vulnerability can affect resources beyond the vulnerable component itself. EXPLOITATION STATUS No active exploitation has been reported. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and shows no community attention on threat intelligence hot lists. The extremely low EPSS score of 0.00029 indicates minimal likelihood of exploitation in the wild, suggesting the vulnerability remains largely unnoticed by threat actors. However, the straightforward nature of the attack vector means proof-of-concept code could be rapidly developed if the vulnerability gains visibility.

Impacted Technologies

VendorProductVersion(s)CPE
<= 26.0CPE matchmatch criteria
cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
9.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 9th percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-rqp3-gf5h-mrqxmedium

WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page

Apr 8, 2026

References

github.com / WWBN/AVideo/commit/e0212add4aad0f1e97758a4b4fdc57df58ce68e8
Patch
github.com / WWBN/AVideo/security/advisories/GHSA-rqp3-gf5h-mrqx
Third Party Advisory