Cross-Site Scripting Flaw in YetAnotherForum.NET Forum Software
CVE-2026-43938

8.1HIGH

Key Information:

Vendor

Yafnet

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-43938?

A vulnerability exists in YetAnotherForum.NET due to improper handling of the User-Agent header during event logging. This flaw allows the application to serialize and then deserialize user input without adequate validation, exposing the application to cross-site scripting attacks. When an event is logged, the unencoded User-Agent information is inserted directly into HTML, enabling potential attackers to execute arbitrary scripts in a user's browser. This issue is addressed in versions 4.0.5 and 3.2.12, which implement necessary security measures to mitigate the risk.

Affected Version(s)

YAFNET >= 4.0.0-beta.1, < 4.0.5 < 4.0.0-beta.1, 4.0.5

YAFNET < 3.2.12 < 3.2.12

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.