XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
References
| Link | Resource |
|---|---|
| https://github.com/methosiea/xenforo-2-xss | Exploit Third Party Advisory |
| https://xenforo.com/community/threads/xenforo-2-3-10-add-ons-and-2-2-19-released-includes-security-fix.236249/ | Release Notes |
Configurations
Configuration 1 (hide)
|
History
01 Apr 2026, 16:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | |
| First Time |
Xenforo
Xenforo xenforo |
|
| References | () https://github.com/methosiea/xenforo-2-xss - Exploit, Third Party Advisory | |
| References | () https://xenforo.com/community/threads/xenforo-2-3-10-add-ons-and-2-2-19-released-includes-security-fix.236249/ - Release Notes | |
| Summary |
|
01 Apr 2026, 03:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Apr 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 01:16
Updated : 2026-04-01 16:24
NVD link : CVE-2026-35057
Mitre link : CVE-2026-35057
CVE.ORG link : CVE-2026-35057
JSON object : View
Products Affected
xenforo
- xenforo
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
