Loading
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
Cite this page
CVE-2026-35055. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-35055
Use CWE-79, Xenforo vendor hub and Xenforo product page to widen CVE-2026-35055 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-71279, CVE-2024-38458 and CVE-2024-38457 for nearby disclosures in the same product family.