Junglewise Threat Intelligence

CVE-2026-43939: YAFNET YetAnotherForum.NET stored XSS in thread posts and replies

CVE-2026-43939 · Severity: high · CVSS 7.3 · Published 2026-05-12

Technologies: YAFNET YetAnotherForum.NET, YAF.NET Core. Vendors: YAFNET, YAF.NET.

Executive brief

YetAnotherForum.NET (YAF.NET) is an open-source forum software used to host community discussions. A security flaw in the thread posting and reply system allows users to inject malicious scripts into their posts. When other users, including administrators, view these posts, the scripts execute automatically in their browsers, potentially leading to account takeover, theft of sensitive session information, or website defacement.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in YetAnotherForum.NET (YAF.NET) due to improper neutralization of user-supplied input in forum posts and replies. The application fails to perform adequate HTML sanitization or contextual output encoding before rendering stored content to other users. An authenticated attacker with standard posting privileges can submit a malicious payload (e.g., using broken image tags with onerror handlers) that executes arbitrary JavaScript in the context of any user viewing the thread. This can be used to steal session cookies, perform unauthorized actions on behalf of administrators, or redirect users to malicious sites. The issue is resolved in versions 4.0.5 and 3.2.12.

Affected products

  • YAFNET YetAnotherForum.NET (YAF.NET) < 4.0.5, < 3.2.12

Timeline

  • 2026-04-26: advisory: GitHub Security Advisory published
  • 2026-05-12: disclosed: CVE published to NVD

References

Related threats