What is CVE-2026-72553?
A stored XSS vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the 'cust_blurb' and 'cust_locate' profile fields, which are rendered unescaped in admin-visible views. Developers should apply HTML encoding to the fields and ensure proper output escaping in profile views.
Azərbaycanca: ElkArte Forum 2.0 Beta 1-də saxlanılmış XSS zəifliyi aşkarlanıb. Bu, qeydiyyatdan keçmiş istənilən üzvə 'cust_blurb' və 'cust_locate' profil sahələrinə JavaScript kodu yeridərək adminlərə qarşı persistent hücum həyata keçirməyə imkan verir. Tərtibatçılar dərhal sahələri HTML encode etməli və profillərdə escape olunmuş şəkildə göstərməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which version of ElkArte Forum contains the stored XSS vulnerability identified as CVE-2026-72553?
This vulnerability was discovered in ElkArte Forum 2.0 Beta 1.
Which profile fields are used to inject JavaScript code in the CVE-2026-72553 exploit?
The JavaScript code is injected into the 'cust_blurb' and 'cust_locate' fields on the profile page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.