Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-41063

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Apr 21, 2026
Vendor unknown

Description

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URLs in markdown link syntax to bypass sanitization. Commit cae8f0dadbdd962c89b91d0095c76edb8aadcacf contains an updated fix.

References