Unrated severityOSV Advisory· Published Dec 18, 2025· Updated Dec 18, 2025
CVE-2025-67163
CVE-2025-67163
Description
A stored cross-site scripting (XSS) vulnerability in Simple Machines Forum v2.1.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Forum Name parameter.
Affected products
1- Range: 2.1beta1, v2.1-beta.1, v2.1-beta.2, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.