OVERVIEW CVE-2026-39367 is a stored cross-site scripting (XSS) vulnerability affecting WWBN AVideo version 26.0 and prior. The vulnerability exists in the EPG (Electronic Program Guide) feature, which parses XML from user-controlled URLs without proper sanitization. An attacker with upload permissions can inject malicious JavaScript code into XML title elements, which executes when unauthenticated visitors view the public EPG page. SEVERITY The vulnerability requires network access and low privilege (upload permission) but presents straightforward attack complexity. With a CVSS score of 5.4 (Medium), the impact includes low confidentiality and integrity risk through session hijacking and potential account takeover of administrative or authenticated users. The attack requires user interaction (victims must visit the EPG page), and the scope is changed, meaning the vulnerability can affect resources beyond the vulnerable component itself. EXPLOITATION STATUS No active exploitation has been reported. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and shows no community attention on threat intelligence hot lists. The extremely low EPSS score of 0.00029 indicates minimal likelihood of exploitation in the wild, suggesting the vulnerability remains largely unnoticed by threat actors. However, the straightforward nature of the attack vector means proof-of-concept code could be rapidly developed if the vulnerability gains visibility.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.