CVE-2026-35057 - Vulnerability Analysis
MediumCVSS: 6.4Last Updated: April 1, 2026
XenForo - Stored XSS
Published: April 1, 2026Updated: April 1, 2026PoC AvailableRemote Exploitable
Overview
XenForo < 2.3.10 and < 2.2.19 contains a stored XSS caused by crafted structured text mentions in legacy profile post content, letting attackers inject malicious scripts executed by other users, exploit requires crafted mentions.
Severity & Score
Severity: Medium
CVSS Score: 6.4
Impact
Attackers can execute malicious scripts in other users' browsers, potentially stealing data or performing actions on their behalf.
Mitigation
Update to version 2.3.10 or 2.2.19 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-35057
- Severity
- Medium
- CVSS Score
- 6.4
- Type
- stored_xss
- Status
- confirmed
CWE
- CWE-79
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N