CVE-2024-58292

XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 22:15

Updated : 2025-12-12 15:17


NVD link : CVE-2024-58292

Mitre link : CVE-2024-58292

CVE.ORG link : CVE-2024-58292


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')