
CVE-2026-35054 XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that ar… https://www.cve.org/CVERecord?id=CVE-2026-35054
Post summary
CVE-2026-35054 reveals a stored XSS flaw in XenForo <2.3.9’s BB code rendering, but the text offers no PoC, exploit code, active exploitation claim, or patch guidance.

