Cross-Site Scripting Vulnerability in Forem by Forem
CVE-2026-61696

6.3MEDIUM

Key Information:

Vendor

Forem

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-61696?

Forem is an open-source platform designed for building online communities. Prior to a specific commit, an XSS vulnerability existed where unsanitized input was accepted through the feedback mechanism. When an administrator viewed certain reports, malicious scripts could execute in their browser, potentially revealing sensitive information or allowing unauthorized actions. This significant security flaw was exploitable by unauthenticated attackers due to insufficient access controls in the FeedbackMessagesController. The issue has been addressed in a subsequent commit.

Affected Version(s)

forem < 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.