XenForo before 2.3.9 is vulnerable to stored cross-site scripting (XSS) related to BB code rendering. An attacker can inject malicious scripts through BB code that are stored and executed when other users view the content.
| Vendor | Product | Versions |
|---|---|---|
| xenforo | xenforo | < 2.3.9 |