PT-2026-29432 · Xenforo · Xenforo

Metho

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-35057

CVSS v3.1

6.4

Medium

AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-35057

Affected Products

Xenforo