Home
Description
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.
References
github.com/...es/SMF/security/advisories/GHSA-p2xm-x9fp-5r7x
github.com/.../release-3.0/Themes/default/Stats.template.php
wiki.simplemachines.org/smf/Installing
github.com/...ulnerability-research/tree/main/CVE-2025-67163
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.