Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-73319

MEDIUM NVD
CVSS Score 6.1
Severity MEDIUM
Published Sep 08, 2026
Vendor unknown

Description

XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthenticated attackers to execute arbitrary JavaScript in the board origin by crafting a malicious javascript: URI that bypasses host validation. Attackers can embed the board hostname in the URI authority component and use percent-encoded newlines to evade server-side filters, causing authenticated users who perform a Follow action to execute attacker-supplied JavaScript in their browser.

References