MEDIUM
ElkArte Forum
CVE published 2026-08-11
CVE-2026-72553
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:40.980Z and has not been modified since then. This stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows registered members to inject persistent JavaScript into profile fields (cust_blurb and cust_locate). These fields are saved without HTML encoding and rendered unes [truncated]