๐Ÿ” CVE Alert

CVE-2026-72553

MEDIUM 5.4

ElkArte Forum ElkArte - Cross-Site Scripting

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile fields cust_blurb and cust_locate. The fields are saved without HTML encoding and rendered unescaped in profile views visible to administrators. An attacker can craft a payload that executes in an administrator session, enabling session hijacking or privilege escalation.

CWE CWE-79
Vendor elkarte forum
Product elkarte
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for elkarte forum elkarte

Be the first to know when new medium vulnerabilities affecting elkarte forum elkarte are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ElkArte Forum / ElkArte
0 โ‰ค 2.0 Beta 1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/elkarte/Elkarte

Credits

Bobur Abdugafforov