Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox. | |
| Title | XenForo Cross-Site Scripting via Lightbox in Posts | |
| First Time appeared |
Xenforo
Xenforo xenforo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:xenforo:xenforo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xenforo
Xenforo xenforo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-01T15:51:58.760Z
Reserved: 2026-04-01T00:19:59.194Z
Link: CVE-2026-35055
Updated: 2026-04-01T14:55:19.525Z
Status : Analyzed
Published: 2026-04-01T01:16:41.397
Modified: 2026-04-01T18:55:13.727
Link: CVE-2026-35055
No data.
OpenCVE Enrichment
Updated: 2026-04-02T20:18:41Z