1

(38 replies, posted in Supported extensions)

XSS:

If thread title has javascript, it will be executed, when you click on thread in "Post approval" (admin/moderator panel).

Line 1023. Temporary fix is to add forum_htmlencode() call to $forum_page['item_subject'].