CVE-2026-43939
HIGHYAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution for All Thread Viewers
Title source: cnaDescription
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This vulnerability is fixed in 4.0.5 and 3.2.12.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/YAFNET/YAFNET/security/advisories/GHSA-8rq5-wwpp-fmj2
Scores
CVSS v3
7.3
EPSS
0.0003
EPSS Percentile
9.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-116
CWE-79
CWE-80
Status
published
Products (4)
nuget/YAFNET.Core
0 - 3.2.12NuGet
nuget/YAFNET.Core
4.0.0-beta01 - 4.0.5NuGet
YAFNET/YAFNET
< 3.2.12
YAFNET/YAFNET
>= 4.0.0-beta.1, < 4.0.5
Published
May 12, 2026
Tracked Since
May 12, 2026