CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. See the original NVD description below for full technical details.
CVE
CVE-2026-35055
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%
Original NVD Description
XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
Related CVEs
Other vulnerabilities affecting the same vendor(s)