CVE-2026-37503

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
01/05/2026
Last modified:
11/05/2026

Description

Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.blade.php. An admin can inject arbitrary JavaScript via the saveThemeConfig API. All site visitors execute the payload, enabling cookie theft, session hijacking, or phishing.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:v2board:v2board:*:*:*:*:*:*:*:* 1.7.4 (including)