Junglewise Threat Intelligence

CVE-2026-54221: UBB Systems UBB.threads Reflected XSS

CVE-2026-54221 · Severity: info · CVSS 5.1 · Published 2026-06-18

Technologies: UBB Systems UBB.threads. Vendors: UBB Systems.

Executive brief

UBB.threads, a forum and community software platform, is vulnerable to a security flaw that could allow attackers to run malicious scripts in a user's browser. By tricking a victim into clicking a specially crafted link, an attacker could potentially steal session information or perform actions on the user's behalf. This issue is particularly concerning as the vendor has not responded to reports, and a fix may not be available.

Technical details

UBB.threads (confirmed in version 7.7.5 and likely earlier) is vulnerable to Reflected Cross-Site Scripting (XSS) because the application improperly sanitizes user-supplied input in certain HTTP requests. An unauthenticated remote attacker can exploit this by convincing a user to click a malicious URL containing a crafted payload. If successful, the attacker can execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch has been confirmed.

Affected products

  • UBB Systems UBB.threads All versions through 7.7.5

Timeline

  • 2026-06-18: advisory: Initial disclosure by CERT Polska

References

Related threats