CVE-2026-54221 PUBLISHED

Reflected XSS in UBB.threads

Assigner: CERT-PL
Reserved: 12.06.2026 Published: 18.06.2026 Updated: 18.06.2026

UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitrary JavaScript in the context of a victim's browser by tricking them into clicking a crafted link.  Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor UBB Systems
Product UBB.threads
Versions Default: unknown
  • affected from 0 to 7.7.5 (incl.)

Credits

  • Kamil Szczurowski (Securitum) finder
  • Michał Wnękowicz (Securitum) finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE

Impacts

  • CAPEC-591 Reflected XSS