XenForo before 2.3.9 and before 2.2.18 is vulnerable to cross-site scripting (XSS) related to lightbox usage in posts. An attacker can inject malicious scripts that execute when users interact with post content displayed in the lightbox.
| Vendor | Product | Versions |
|---|---|---|
| xenforo | xenforo | 2.3.0, 0 |
Updated affected versions to 2.2.17 and 2.3.8, changed severity to HIGH, and noted that no exploit is available.
Initial creation