๐Ÿ” CVE Alert

CVE-2024-58344

MEDIUM 6.4

Carbon Forum 5.9.0 Persistent XSS via Forum Name Field

CVSS Score
6.4
EPSS Score
0.0%
EPSS Percentile
0th

Carbon Forum 5.9.0 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript code through the Forum Name field in dashboard settings. Attackers with admin privileges can store JavaScript payloads in the Forum Name field that execute in the browsers of all users visiting the forum, enabling session hijacking and data theft.

CWE CWE-79
Vendor 94cb
Product carbon forum
Published Apr 22, 2026
Stay Ahead of the Next One

Get instant alerts for 94cb carbon forum

Be the first to know when new medium vulnerabilities affecting 94cb carbon forum are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
None

Affected Versions

94Cb / Carbon Forum
5.9.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/52043 94cb.com: https://www.94cb.com/ github.com: https://github.com/lincanbin/Carbon-Forum vulncheck.com: https://www.vulncheck.com/advisories/carbon-forum-persistent-xss-via-forum-name-field

Credits

Chokri Hammedi