CVE-2026-35057

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*
cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-01 01:16

Updated : 2026-06-17 10:40


NVD link : CVE-2026-35057

Mitre link : CVE-2026-35057

CVE.ORG link : CVE-2026-35057


JSON object : View

Products Affected

xenforo

  • xenforo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')