XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xmb Forum
Xmb Forum xmb Xmbforum2 Xmbforum2 xmb |
|
| Vendors & Products |
Xmb Forum
Xmb Forum xmb Xmbforum2 Xmbforum2 xmb |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XMB Forum 1.9.12.06 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious JavaScript into templates and front page settings. Attackers can insert XSS payloads in footer templates and news ticker fields, enabling script execution for all forum users when pages are rendered. | |
| Title | XMB Forum 1.9.12.06 Persistent Cross-Site Scripting via Admin Templates | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-11T21:35:30.698Z
Reserved: 2025-12-11T00:58:28.456Z
Link: CVE-2024-58292
No data.
Status : Awaiting Analysis
Published: 2025-12-11T22:15:50.107
Modified: 2025-12-12T15:17:31.973
Link: CVE-2024-58292
No data.
OpenCVE Enrichment
Updated: 2025-12-12T08:49:19Z
Weaknesses