Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 11 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:v2board:v2board:*:*:*:*:*:*:*:* |
Sat, 02 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting via Unescaped Theme Configuration in V2Board 1.7.4 |
Fri, 01 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
V2board
V2board v2board |
|
| Vendors & Products |
V2board
V2board v2board |
Fri, 01 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
ssvc
|
Fri, 01 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.blade.php. An admin can inject arbitrary JavaScript via the saveThemeConfig API. All site visitors execute the payload, enabling cookie theft, session hijacking, or phishing. | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-01T19:46:08.026Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-37503
Updated: 2026-05-01T19:40:20.702Z
Status : Analyzed
Published: 2026-05-01T16:16:30.490
Modified: 2026-05-11T19:22:57.067
Link: CVE-2026-37503
No data.
OpenCVE Enrichment
Updated: 2026-05-02T08:15:16Z