CVE-2026-35057

XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*
cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*

History

01 Apr 2026, 16:24

Type Values Removed Values Added
CPE cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:*
First Time Xenforo
Xenforo xenforo
References () https://github.com/methosiea/xenforo-2-xss - () https://github.com/methosiea/xenforo-2-xss - Exploit, Third Party Advisory
References () https://xenforo.com/community/threads/xenforo-2-3-10-add-ons-and-2-2-19-released-includes-security-fix.236249/ - () https://xenforo.com/community/threads/xenforo-2-3-10-add-ons-and-2-2-19-released-includes-security-fix.236249/ - Release Notes
Summary
  • (es) XenForo anterior a 2.3.10 y anterior a 2.2.19 es vulnerable a cross-site scripting (XSS) almacenado en menciones de texto estructurado, afectando principalmente el contenido de publicaciones de perfil heredadas. Un atacante puede inyectar scripts maliciosos a través de menciones elaboradas que se almacenan y ejecutan cuando otros usuarios ven el contenido.

01 Apr 2026, 03:15

Type Values Removed Values Added
References
  • {'url': 'https://www.vulncheck.com/advisories/xenforo-stored-cross-site-scripting-via-structured-text-mentions', 'source': 'disclosure@vulncheck.com'}

01 Apr 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 01:16

Updated : 2026-04-01 16:24


NVD link : CVE-2026-35057

Mitre link : CVE-2026-35057

CVE.ORG link : CVE-2026-35057


JSON object : View

Products Affected

xenforo

  • xenforo
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')