PatchSiren

ElkArte Forum CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ElkArte Forum CVE published 2026-08-11

CVE-2026-72553

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:40.980Z and has not been modified since then. This stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows registered members to inject persistent JavaScript into profile fields (cust_blurb and cust_locate). These fields are saved without HTML encoding and rendered unes [truncated]