CVE Database
/

CVE-2024-58292

Back to search

CVE-2024-58292

Published: Dec 11, 2025

Modified: Apr 7, 2026

PUBLISHED

Description

XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered.

VendorProductVersions

xmbforum2

XMB Forum

affected
1.9.12.06

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now