Back to search
CVE-2024-58292
Published: Dec 11, 2025
Modified: Apr 7, 2026
PUBLISHED
Description
XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered.
| Vendor | Product | Versions |
|---|---|---|
xmbforum2 | XMB Forum | affected 1.9.12.06 |
Weaknesses (CWE)
References
ExploitDB-52044
exploit
XMB Forum Homepage
product
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now