PT-2026-29430 · Xenforo · Xenforo

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-35055

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions XenForo versions prior to 2.3.9 and prior to 2.2.18
Description XenForo is susceptible to cross-site scripting (XSS) due to the way lightbox is used in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
Recommendations Update to XenForo version 2.3.9 or later Update to XenForo version 2.2.18 or later

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-35055

Affected Products

Xenforo