Junglewise Threat Intelligence

CVE-2026-54219: UBB Systems UBB.threads Stored XSS in posts and profile fields

CVE-2026-54219 · Severity: info · CVSS 5.1 · Published 2026-06-18

Technologies: UBB Systems UBB.threads. Vendors: UBB Systems.

Executive brief

UBB.threads, a forum and community software platform, is vulnerable to a security flaw where malicious code can be saved within user posts or profile fields. An attacker with a standard user account can upload harmful scripts that will automatically run in the browsers of other users, including administrators, when they view the affected content. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in UBB.threads due to improper neutralization of user-supplied input in forum posts and user profile fields (CWE-79). An attacker with low-level privileges can inject malicious JavaScript into these fields, which is then stored on the server and executed in the security context of any user who views the compromised content. This vulnerability has been confirmed in version 7.7.5. Because the vendor did not respond to disclosure attempts, no official patch is currently available. The attack requires network access and a valid user account, but relies on a victim viewing the malicious content (User Interaction).

Affected products

  • UBB Systems UBB.threads All versions through 7.7.5

Timeline

  • 2026-06-18: disclosed: Coordinated disclosure by CERT Polska
  • 2026-06-18: advisory

References

Related threats