CVE-2026-33295: AVideo Affected by Stored XSS via Unescaped Video Title in CDN downloadButtons.php
WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin’s download buttons component. The clean_title field of a video record is interpolated directly into a JavaScript string literal without any escaping, allowing an attacker who can create or modify a video to inject arbitrary JavaScript that executes in the browser of any user who visits the affected download page.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33295 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →