XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content. | |
| Title | XenForo Stored Cross-Site Scripting via BB Code Rendering | |
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xenforo
Xenforo xenforo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-01T13:37:39.225Z
Reserved: 2026-04-01T00:19:59.194Z
Link: CVE-2026-35054
Updated: 2026-04-01T13:37:28.687Z
Status : Analyzed
Published: 2026-04-01T01:16:41.200
Modified: 2026-04-01T18:51:19.460
Link: CVE-2026-35054
No data.