CVE-2026-34375 | WWBN AVideo up to 26.0 URL security.php User::getUserName plugin cross site scripting (GHSA-pm37-62g7-p768)
A vulnerability was found in WWBN AVideo up to 26.0 and classified as problematic. Affected by this vulnerability is the function User::getUserName of the file security.php of the component URL Handler. Executing a manipulation of the argument plugin can lead to cross site scripting.
This vulnerability is registered as CVE-2026-34375. It is possible to launch the attack remotely. No exploit is available.
It is advisable to implement a patch to correct this issue.