AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-35055

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-04-01 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. See the original NVD description below for full technical details.

CVE
CVE-2026-35055
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%

Original NVD Description

XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.

Related CVEs

Other vulnerabilities affecting the same vendor(s)