CVE-2026-35055: Xenforo
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
Affected products
- Xenforo Xenforo: before 2.2.18 (fixed in 2.2.18); from 2.3.0, before 2.3.9 (fixed in 2.3.9)
Published 2026-04-01. Last modified 2026-06-17.