GHSA-9c2q-wpvm-f24rCriticalCVSS 8.7

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site...

Published
September 10, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (1)

📋 Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor viewing the live-link page, including administrators, within the site origin.

🔗 References (4)