CVE-2026-35054

MEDIUM

XenForo Stored Cross-Site Scripting via BB Code Rendering

Title source: cna

Description

XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.

Scores

CVSS v3 6.4
EPSS 0.0003
EPSS Percentile 8.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
xenforo/xenforo < 2.3.9
XenForo/XenForo 2.3.0 - 2.3.9
Published Apr 01, 2026
Tracked Since Apr 01, 2026