XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
References
| Link | Resource |
|---|---|
| https://github.com/methosiea/xenforo-2-xss | Exploit Third Party Advisory |
| https://xenforo.com/community/threads/xenforo-2-3-10-add-ons-and-2-2-19-released-includes-security-fix.236249/ | Release Notes |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-01 01:16
Updated : 2026-06-17 10:40
NVD link : CVE-2026-35057
Mitre link : CVE-2026-35057
CVE.ORG link : CVE-2026-35057
JSON object : View
Products Affected
xenforo
- xenforo
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
