CVE-2026-54221
Reflected XSS in UBB.threads
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitrary JavaScript in the context of a victim's browser by tricking them into clicking a crafted link. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.
| CWE | CWE-79 |
| Vendor | ubb systems |
| Product | ubb.threads |
| Published | Jun 18, 2026 |
| Last Updated | Jun 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for ubb systems ubb.threads
Be the first to know when new unknown vulnerabilities affecting ubb systems ubb.threads are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
UBB Systems / UBB.threads
0 ≤ 7.7.5
References
Credits
Kamil Szczurowski (Securitum) Michał Wnękowicz (Securitum)