Cross-site scripting in AVideo - CVE-2026-34375
Published: May 4, 2026
AVideo
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in a user's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the YPTWallet Stripe payment page when handling a plugin parameter. A remote attacker can supply a specially crafted parameter value to execute arbitrary script in a user's browser.
User interaction is required to load the crafted page or URL.