CVE-2008-5399
mvnForum <1.2.1 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
References (7)
Scores
EPSS
0.0047
EPSS Percentile
64.5%
Classification
CWE
CWE-79
Status
published
Affected Products (11)
mvnforum/mvnforum
< 1.2
mvnforum/mvnforum
mvnforum/mvnforum
mvnforum/mvnforum
mvnforum/mvnforum
mvnforum/mvnforum
mvnforum/mvnforum
mvnforum/mvnforum
mvnforum/mvnforum
mvnforum/mvnforum
n/a/n/a
Timeline
Published
Dec 10, 2008
Tracked Since
Feb 18, 2026