YAFNET是YAFNET个人开发者的ASP.NET 开源论坛解决方案。 YAFNET 4.0.5之前版本和3.2.12之前版本存在跨站脚本漏洞,该漏洞源于帖子发布和回复功能未进行充分的HTML清理或输出编码,可能导致存储型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43937 | 8.8 HIGH | YAF.NET: Pre-Handler Authorization Bypass on Admin Pages Enabling Blind SQL Execution via |
| CVE-2026-43938 | 8.1 HIGH | YAF.NET: Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-Ag |
No comments yet