CVE-2026-35055

Publication date

2026-04-01 00:30:13

Family

VulnCheck

State

PUBLISHED

Description

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.