Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 21 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ubb Systems
Ubb Systems ubb.threads |
|
| Vendors & Products |
Ubb Systems
Ubb Systems ubb.threads |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling attackers to execute arbitrary JavaScript in the context of a victim's browser by tricking them into clicking a crafted link. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 7.7.5 but may also affect other versions. | |
| Title | Reflected XSS in UBB.threads | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-06-18T13:30:11.277Z
Reserved: 2026-06-12T11:03:23.916Z
Link: CVE-2026-54221
Updated: 2026-06-18T13:29:57.168Z
Status : Deferred
Published: 2026-06-18T14:17:30.663
Modified: 2026-06-18T18:05:54.947
Link: CVE-2026-54221
No data.
OpenCVE Enrichment
Updated: 2026-06-20T22:56:13Z