Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/elkarte/Elkarte |
|
Tue, 11 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile fields cust_blurb and cust_locate. The fields are saved without HTML encoding and rendered unescaped in profile views visible to administrators. An attacker can craft a payload that executes in an administrator session, enabling session hijacking or privilege escalation. | |
| Title | ElkArte Forum ElkArte - Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T15:16:23.690Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72553
Updated: 2026-08-11T15:16:19.195Z
Status : Received
Published: 2026-08-11T12:17:40.980
Modified: 2026-08-11T16:17:35.680
Link: CVE-2026-72553
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:15:06Z