CVE-2023-53904: Xenforo

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin panel is loaded, potentially enabling further client-side attacks.

Affected products

  • Xenforo Xenforo: version 2.2.13 only

Published 2025-12-17. Last modified 2026-06-17.