[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#AVideo

newsHIGH 7.5

Authorization Bypass Vulnerability in WWBN AVideo (CVE-2026-59256)

A vulnerability in WWBN AVideo allows attackers to bypass authorization checks by retrieving a token from the Gallery endpoint, affecting video content access. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. AVideo users should update to a fixed version to mitigate this risk.

Aug 23, 20261 source
blogMEDIUM 6.1

Understanding and Defending Against Stored Cross-Site Scripting (XSS) in AVideo TopMenu Plugin

This educational analysis covers CVE-2026-56347, a stored cross-site scripting vulnerability in the AVideo TopMenu plugin through version 26.0. The vulnerability allows attackers to inject malicious JavaScript through unescaped menu item fields, potentially stealing session cookies or performing unauthorized actions on all site visitors. We will delve into the root cause, attack surface, exploitation mechanics, real-world impact, and defensive strategies.

Jun 21, 20261 source