Aller au contenu

Fiche vulnérabilité

CVE-2026-35057 : faille moyenne xenforo xenforo (CVSS 5.4)

Description

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
1 avr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • xenforo xenforo

Références

Rechercher une autre vulnérabilité dans la base CVE