Cross-Site Scripting Flaw in YetAnotherForum.NET Forum Software
CVE-2026-43938
8.1HIGH
What is CVE-2026-43938?
A vulnerability exists in YetAnotherForum.NET due to improper handling of the User-Agent header during event logging. This flaw allows the application to serialize and then deserialize user input without adequate validation, exposing the application to cross-site scripting attacks. When an event is logged, the unencoded User-Agent information is inserted directly into HTML, enabling potential attackers to execute arbitrary scripts in a user's browser. This issue is addressed in versions 4.0.5 and 3.2.12, which implement necessary security measures to mitigate the risk.
Affected Version(s)
YAFNET >= 4.0.0-beta.1, < 4.0.5 < 4.0.0-beta.1, 4.0.5
YAFNET < 3.2.12 < 3.2.12
