CVE-2026-35055
EUVD-2026-1774101.04.2026, 01:16
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| xenforo | xenforo | 𝑥 < 2.2.18 |
| xenforo | xenforo | 2.3.0 ≤ 𝑥 < 2.3.9 |
𝑥
= Vulnerable software versions