CVE-2026-28558
EUVD-2026-910728.02.2026, 22:16
wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gvectors | wpforo_forum | 2.4.0 ≤ 𝑥 < 2.4.16 |
𝑥
= Vulnerable software versions