216.73.216.6

CVE-2026-35057

· Published 01/04/2026 01:16 · Modified 01/04/2026 16:24

Labels: CVE-2026-35057 2026-04-01CVE-2026-35057CWE-79[email protected]

Essential information

Published
01/04/2026 01:16
Modified
01/04/2026 16:24
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
xenforo / xenforo cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*
xenforo / xenforo cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

References