Skip to main content
CRITICAL

CVE-2026-88869

CVSS v3

9.3

CRITICAL

EPSS Score

0.5 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execution of arbitrary JavaScript in an administrator's browser session.

Technical details

Published
2026-09-10
Last Modified
2026-09-10

Frequently asked questions

What is CVE-2026-88869?

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later rendered unsanitized in the admin Ad Types report using jQuery .html(), allowing execution of arbitrary JavaScript in an administrator's browser session.

Is CVE-2026-88869 actively exploited?

Active exploitation of CVE-2026-88869 has not been confirmed. Its EPSS score was 0.5% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-88869?

CVE-2026-88869 has a CVSS v3 base score of 9.3 (CRITICAL severity).

Is CVE-2026-88869 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key