
CVE-2026-35055 XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that e… https://www.cve.org/CVERecord?id=CVE-2026-35055
Post summary
The post announces CVE-2026-35055, an XSS vulnerability in XenForo before versions 2.3.9 and 2.2.18, without providing exploit details, patches, or any evidence of current exploitation.

