Junglewise Threat Intelligence

CVE-2026-37503: V2Board stored XSS in theme configuration custom_html

CVE-2026-37503 · Severity: medium · CVSS 6.9 · Published 2026-05-01

Technologies: V2board. Vendors: V2board.

Executive brief

V2Board is a management panel used for proxy protocol services. A security vulnerability exists where an administrator can inject malicious scripts into the dashboard's theme configuration. If exploited, these scripts will run in the browsers of all site visitors, potentially allowing the attacker to steal login sessions, hijack accounts, or perform phishing attacks against users.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in V2Board versions up to and including 1.7.4. The root cause is the use of unescaped Blade interpolation ({!! !!}) for the 'custom_html' field within the dashboard.blade.php template. An attacker with administrative privileges can use the saveThemeConfig API to inject arbitrary JavaScript. Because the payload is rendered on the dashboard, it executes in the context of any user (including other admins and site visitors) who views the page. This can lead to session hijacking via cookie theft or unauthorized actions performed on behalf of the victim. The project is reportedly unmaintained, and no official patch is available; users are advised to manually switch to escaped output ({{ }}) in the affected Blade template.

Affected products

  • V2Board V2Board up to and including 1.7.4

Timeline

  • 2026-04-30: disclosed: Vulnerability reported by Innora Security Research
  • 2026-05-01: advisory: CVE-2026-37503 published

References

Related threats