Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 10 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allowing script execution within the administrator session. | |
| Title | WWBN AVideo LoginControl Stored XSS via User-Agent Header | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-10T13:05:21.890Z
Reserved: 2026-09-10T11:23:56.027Z
Link: CVE-2026-88866
No data.
Status : Received
Published: 2026-09-10T14:17:12.773
Modified: 2026-09-10T14:17:12.773
Link: CVE-2026-88866
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')