Back to CVE List

CVE-2026-35057

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.4 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Vulnerability Description

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-79
Source
NVD
Vendor
XenForo
Product
XenForo

External References

Discussion (0)

Add Comment

No comments yet. Be the first!