CVE-2023-53904: Xenforo
Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin panel is loaded, potentially enabling further client-side attacks.
Affected products
- Xenforo Xenforo: version 2.2.13 only
Published 2025-12-17. Last modified 2026-06-17.