Altium Forum Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Altium Forum. This issue arises from inadequate server-side input sanitization in forum post content, allowing authenticated attackers to inject arbitrary JavaScript. The injected scripts are executed when other users view the affected posts. Exploitation of this vulnerability requires user interaction to access the malicious forum post. Once executed, the attacker's payload runs in the context of the victim's authenticated Altium 365 session, potentially leading to unauthorized access to workspace data, including design files and workspace settings.

Impact

Exploitation allows injected JavaScript to execute in the context of the victim's Altium 365 session, potentially accessing sensitive workspace data such as design files and workspace settings.

Added: Jan 15, 2026, 11:26 PM
Updated: Jan 15, 2026, 11:26 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.0
remediation
0.0
relevance
2.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.