HIGHVulnerability

CVE-2026-72747

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in the database. When administrators visit the users management page, the unsanitized phone value is rendered via innerHTML, executing the injected script in the admin's browser session.

Properties

severity
HIGH
score
7.2
epss_score
0.00259
cve_id
CVE-2026-72747
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
published_at
2026-08-11T13:19:05.663
last_modified
2026-09-08T20:32:39.347
epss_percentile
0.17474

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72747 — Ninja Signal Threat Intelligence | Ninja Signal