XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content. | |
| Title | XenForo Stored Cross-Site Scripting via BB Code Rendering | |
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xenforo
Xenforo xenforo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-01T01:43:23.018Z
Reserved: 2026-04-01T00:19:59.194Z
Link: CVE-2026-35054
No data.
Status : Received
Published: 2026-04-01T01:16:41.200
Modified: 2026-04-01T01:16:41.200
Link: CVE-2026-35054
No data.
OpenCVE Enrichment
No data.