Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and previous versions allows remote malicious users to inject arbitrary Javascript via the BBCode color value.