Vulnerability Description
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and later rendered back into the thread page without adequate HTML sanitization or contextual output encoding. This vulnerability is fixed in 4.0.5 and 3.2.12.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/YAFNET/YAFNET/security/advisories/GHSA-8rq5-wwpp-fmj2
- https://github.com/YAFNET/YAFNET/security/advisories/GHSA-8rq5-wwpp-fmj2
FAQ
What is CVE-2026-43939?
CVE-2026-43939 is a vulnerability with a CVSS score of 7.3 (HIGH). YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and ...
How severe is CVE-2026-43939?
CVE-2026-43939 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-43939?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.