WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a video's epg_link to a malicious XML file whose <title> elements contain JavaScript. This payload executes in the browser of any unauthenticated visitor to the public EPG page, enabling session hijacking and account takeover.
Cite this page
CVE-2026-39367. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-39367
Use CWE-79, Wwbn vendor hub and Avideo product page to widen CVE-2026-39367 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-41064, CVE-2026-41304 and CVE-2026-41055 for nearby disclosures in the same product family.