CVE-2023-53904

Publication date

2025-12-17 22:44:43

Family

VulnCheck

State

PUBLISHED

Description

Xenforo 2.2.13 contains a stored cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the smilie category title parameter. Attackers can create a smilie category with a malicious script that will execute when the admin panel is loaded, potentially enabling further client-side attacks.