HarborGuard / CVE
Back to search
HIGHCVE-2026-43939Published Modified CNA GitHub_M

CVE-2026-43939: YAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution for All Thread Viewers

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This vulnerability is fixed in 4.0.5 and 3.2.12.

Metrics

CVSS v3.1
7.3
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • YAFNET / YAFNET
    >= 4.0.0-beta.1, < 4.0.5 · < 3.2.12
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N