CVE-2017-2243: Dfactory Responsive Lightbox

Medium severity, CVSS 6.1. EPSS: 1.5% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

Affected products

  • Dfactory Responsive Lightbox: up to and including 1.7.1

Published 2017-07-07. Last modified 2026-06-17.