CRITICAL 9.3 CVE-2026-88869 Published 10 Sept 2026

AVideo AD_Server Plugin XSS Vulnerability

Worried this affects one of your servers?

AVideo CMS, through commit c3edcc2, has a stored cross-site scripting (XSS) vulnerability in the AD_Server plugin's log.php endpoint.

The vulnerability occurs due to insufficient escaping of the 'label' parameter, allowing an unauthenticated attacker to inject malicious HTML.

This injected HTML is later rendered unsanitized in the admin Ad Types report using jQuery .html(), enabling the execution of arbitrary JavaScript in an administrator's browser session.

Reference: CVE-2026-88869 on NVD

← Back to Security News