CVE-2026-35057: XenForo Stored Cross-Site Scripting via Structured Text Mentions
XenForo before 2.3.10 and before 2.2.19 is vulnerable to stored cross-site scripting (XSS) in structured text mentions, primarily affecting legacy profile post content. An attacker can inject malicious scripts through crafted mentions that are stored and executed when other users view the content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35057?
The severity of CVE-2026-35057 is rated as high due to its potential to enable stored cross-site scripting attacks.
How do I fix CVE-2026-35057?
To fix CVE-2026-35057, upgrade to XenForo version 2.3.10 or 2.2.19 or later.
What kind of attack does CVE-2026-35057 enable?
CVE-2026-35057 enables stored cross-site scripting (XSS) attacks through crafted structured text mentions.
Which versions of XenForo are affected by CVE-2026-35057?
CVE-2026-35057 affects XenForo versions prior to 2.3.10 and 2.2.19.
What is the main impact of CVE-2026-35057?
The main impact of CVE-2026-35057 is the potential for attackers to inject and execute malicious scripts in user contexts.