CVE-2026-35054: XenForo Stored Cross-Site Scripting via BB Code Rendering
XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35054?
The severity of CVE-2026-35054 is classified as high due to its potential to allow attackers to execute malicious scripts.
How do I fix CVE-2026-35054?
To fix CVE-2026-35054, upgrade XenForo to version 2.3.9 or later to mitigate the stored cross-site scripting vulnerability.
What type of vulnerability is CVE-2026-35054?
CVE-2026-35054 is a stored cross-site scripting (XSS) vulnerability related to BB code rendering in XenForo.
Who is affected by CVE-2026-35054?
Users of XenForo versions prior to 2.3.9 are affected by CVE-2026-35054.
What can attackers achieve with CVE-2026-35054?
Attackers can exploit CVE-2026-35054 to inject and execute malicious scripts when other users view the affected content.