Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in AVideo - #VU125501
Published: April 8, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in TopMenu plugin menu item fields when rendering stored menu item content. A remote attacker can inject a specially crafted script payload to execute arbitrary script code in a victim's browser.
User interaction is required for a victim to view the affected content.