Security Advisory
CVE-2026-39367
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideos EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly into HTML without any sanitization or escaping. A user with upload permission can set a videos epg_link to a malicious XML file whose <title> elements contain JavaScript. This payload executes in the browser of any unauthenticated visitor to the public EPG page, enabling session hijacking and account takeover.