CVE-2026-89253
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 has a stored cross-site scripting flaw in the donationLink profile field. An authenticated user can inject JavaScript that runs in a visitor's browser when that visitor interacts with the donation button on the user's watch page, potentially affecting an administrator.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 when the CustomizeUser allowDonationLink option is enabled. No affected products were listed in the CPE data provided.
Real-world impact
The issue has a CVSS base score of 9.3 and is rated critical. Successful exploitation can expose or alter data accessible in the affected visitor's browser.
Why this severity
Critical
What to do about it
- ›Disable the CustomizeUser allowDonationLink option so the affected donation button is not included on watch pages.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources