Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 11 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators viewing pending withdrawal requests in pendingRequests.php execute the stored markup in their session, allowing attackers to perform administrative actions via same-origin fetch requests. | |
| Title | AVideo YPTWallet Stored XSS via CryptoWallet Configuration | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-11T11:15:27.995Z
Reserved: 2026-09-11T10:51:59.214Z
Link: CVE-2026-89249
No data.
Status : Received
Published: 2026-09-11T12:16:54.890
Modified: 2026-09-11T12:16:54.890
Link: CVE-2026-89249
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')