Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 30 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescaped markup, then deliver it as a legitimate-looking link on the site's own domain to execute JavaScript in victims' sessions and steal cookies or CSRF tokens. | |
| Title | WWBN AVideo Unauthenticated Reflected XSS via url2Embed.json.php | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-30T14:33:29.680Z
Reserved: 2026-08-30T13:38:00.101Z
Link: CVE-2026-82646
No data.
Status : Received
Published: 2026-08-30T15:16:45.013
Modified: 2026-08-30T15:16:45.013
Link: CVE-2026-82646
No data.
OpenCVE Enrichment
Updated: 2026-08-30T16:30:17Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')