๐Ÿ” CVE Alert

CVE-2026-61696

MEDIUM 6.3

Forem: Stored XSS in Admin Abuse Report Rendering

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitted through feedback_message[message] is stored without sanitization and rendered in app/views/admin/feedback_messages/_feedback_message.html.erb through raw(feedback_message.message) when offender_id is present. Viewing the abuse report executes arbitrary JavaScript in an administrator's browser and may expose sensitive in-page data, abuse CSRF tokens, or perform administrative actions in the victim's session. The public FeedbackMessagesController accepts the report without authorization and previously permitted a submitted offender_id, making the vulnerable rendering path reachable by an unauthenticated attacker. This issue is fixed in commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c

CWE CWE-74 CWE-79 CWE-116
Vendor forem
Product forem
Published Aug 18, 2026
Last Updated Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for forem forem

Be the first to know when new medium vulnerabilities affecting forem forem are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

forem / forem
< 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/forem/forem/security/advisories/GHSA-4463-499m-94mx github.com: https://github.com/forem/forem/commit/92eacd16a82cf9007ba8e16a2258b42e3b53ca9c