CVE-2026-35055

MEDIUM

XenForo Cross-Site Scripting via Lightbox in Posts

Title source: cna

Description

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.

Scores

CVSS v3 6.1
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
XenForo/XenForo < 2.2.18
xenforo/xenforo < 2.2.18
XenForo/XenForo 2.3.0 - 2.3.9
Published Apr 01, 2026
Tracked Since Apr 01, 2026