Medium severity6.1NVD Advisory· Published Apr 3, 2024· Updated Jun 17, 2026
CVE-2024-26495
CVE-2024-26495
Description
Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
1- github.com/friendica/friendica/issues/13884nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.