PT-2026-29429 · Xenforo · Xenforo

Antisocial

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-35054

CVSS v3.1

6.4

Medium

AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-35054

Affected Products

Xenforo