LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-35057

CVE-2026-35057 - Vulnerability Analysis

MediumCVSS: 6.4

Last Updated: April 1, 2026

XenForo - Stored XSS

Published: April 1, 2026Updated: April 1, 2026PoC AvailableRemote Exploitable

Overview

XenForo < 2.3.10 and < 2.2.19 contains a stored XSS caused by crafted structured text mentions in legacy profile post content, letting attackers inject malicious scripts executed by other users, exploit requires crafted mentions.

Severity & Score

Severity: Medium
CVSS Score: 6.4

Impact

Attackers can execute malicious scripts in other users' browsers, potentially stealing data or performing actions on their behalf.

Mitigation

Update to version 2.3.10 or 2.2.19 or later.

Details

CVE ID
CVE-2026-35057
Severity
Medium
CVSS Score
6.4
Type
stored_xss
Status
confirmed

CWE

  • CWE-79

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N