CVE-2013-5309: Fudforum

Low severity, CVSS 2.6. EPSS: 1.2% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, when registering a new user, allows remote attackers to inject arbitrary web script or HTML via a custom profile field to index.php. NOTE: some of these details are obtained from third party information.

Affected products

  • Fudforum Fudforum: up to and including 3.0.4.1; version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; version 2.7.5 only; version 2.7.6 only; …
  • Ilia Alshanetsky Fudforum: version 1.2.8 only; version 1.9.8 only; version 2.0.2 only; version 2.1.0 only; version 2.1.1 only; version 2.1.2 only; …

Published 2013-08-16. Last modified 2026-06-16.