CVE-2026-43939

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This vulnerability is fixed in 4.0.5 and 3.2.12.
Configurations

No configuration.

History

13 May 2026, 16:16

Type Values Removed Values Added
References () https://github.com/YAFNET/YAFNET/security/advisories/GHSA-8rq5-wwpp-fmj2 - () https://github.com/YAFNET/YAFNET/security/advisories/GHSA-8rq5-wwpp-fmj2 -

12 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 15:16

Updated : 2026-05-13 18:24


NVD link : CVE-2026-43939

Mitre link : CVE-2026-43939

CVE.ORG link : CVE-2026-43939


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CWE-116

Improper Encoding or Escaping of Output