XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versions of XMB. All XMB installations must be updated to versions 1.9.12.03 or 1.9.11.16.
| Software | From | Fixed in |
|---|---|---|
| xmbforum2 / xmb | 1.9.1 | 1.9.11.16 |
| xmbforum2 / xmb | 1.9.11 | 1.9.11.16 |
| xmbforum2 / xmb | 1.9.12 | 1.9.12.03 |