Fiche vulnérabilité
CVE-2026-35057 : faille moyenne xenforo xenforo (CVSS 5.4)
Description
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
En bref
- Sévérité
- Moyenne (CVSS 5.4)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 1 avr. 2026
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- xenforo xenforo