PT-2026-29360 · Unknown+1 · Jquery Toast Plugin+1

Adrgs

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34716

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 26.0 and prior
Description The AVideo YPTSocket plugin's caller feature in versions 26.0 and prior renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the heading parameter. The toast plugin constructs the heading as raw HTML and inserts it into the DOM via jQuery's .html() method, which parses and executes any embedded HTML or script content. An attacker can set their display name to a cross-site scripting (XSS) payload and trigger code execution on any online user's browser simply by initiating a call. No victim interaction is required beyond being connected to the WebSocket.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34716
GHSA-W4HP-W536-JG64

Affected Products

Avideo
Jquery Toast Plugin