YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This vulnerability is fixed in 4.0.5 and 3.2.12.
References
Configurations
No configuration.
History
13 May 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/YAFNET/YAFNET/security/advisories/GHSA-8rq5-wwpp-fmj2 - |
12 May 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-12 15:16
Updated : 2026-05-13 18:24
NVD link : CVE-2026-43939
Mitre link : CVE-2026-43939
CVE.ORG link : CVE-2026-43939
JSON object : View
Products Affected
No product.
