wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 28 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | wpForo Forum 2.4.14 contains a stored cross-site scripting vulnerability that allows authenticated subscribers to upload SVG files as profile avatars through the avatar upload functionality. Attackers upload a crafted SVG containing CSS injection or JavaScript event handlers that execute in the browsers of any user who views the attacker's profile page. | |
| Title | wpForo Forum 2.4.14 Stored XSS via SVG Avatar File Upload | |
| First Time appeared |
Gvectors
Gvectors wpforo Forum |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:*:*:* cpe:2.3:a:gvectors:wpforo_forum:2.4.16:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gvectors
Gvectors wpforo Forum |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-28T21:47:38.290Z
Reserved: 2026-02-28T18:54:23.280Z
Link: CVE-2026-28558
No data.
Status : Received
Published: 2026-02-28T22:16:02.637
Modified: 2026-02-28T22:16:02.637
Link: CVE-2026-28558
No data.
OpenCVE Enrichment
No data.
Weaknesses